Incorrect handling of malformed RFC 1964 tokens allows denial of service against applications using GSSAPI (CVE-2014-4341, CVE-2014-4342)
CVE-2014-4343: double free in SPNEGO initiators
NULL pointer deferences in SPNEGO (CVE-2014-4344)
Incorrect memory management in the libgssapi_krb5 library might result in denial of service or potential execution of arbitrary code (CVE-2014-5352)
Tests (i386): OK Advisory: 2015-03-20-krb5.yaml
The patch relax-build-deps.patch is no longer applied in the updated package. Also, please update the YAML file: The CVE IDs which don't affect UCS (since we use Heimdal KDC/kadmin) should be listed separately with a note that these components are not used in UCS.
(In reply to Moritz Muehlenhoff from comment #5) > The patch relax-build-deps.patch is no longer applied in the updated package. Fixed. Tests (i386): OK > Also, please update the YAML file: The CVE IDs which don't affect UCS (since > we use Heimdal KDC/kadmin) should be listed separately with a note that > these components are not used in UCS. Fixed.
Ok, looks good.
<http://errata.univention.de/ucs/3.2/302.html>