Bug 35263 - krb5: Multiple issues (3.2)
Summary: krb5: Multiple issues (3.2)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 3.2
Hardware: Other Linux
: P3 normal
Target Milestone: UCS 3.2-5-errata
Assignee: Janek Walkenhorst
QA Contact: Moritz Muehlenhoff
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-07-04 14:51 CEST by Moritz Muehlenhoff
Modified: 2015-03-25 14:03 CET (History)
1 user (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Moritz Muehlenhoff univentionstaff 2014-07-04 14:51:12 CEST
Incorrect handling of malformed RFC 1964 tokens allows denial of service against applications using GSSAPI (CVE-2014-4341, CVE-2014-4342)
Comment 1 Moritz Muehlenhoff univentionstaff 2014-07-22 07:21:00 CEST
CVE-2014-4343: double free in SPNEGO initiators
Comment 2 Moritz Muehlenhoff univentionstaff 2015-01-05 11:29:05 CET
NULL pointer deferences in SPNEGO (CVE-2014-4344)
Comment 3 Moritz Muehlenhoff univentionstaff 2015-02-04 08:05:58 CET
Incorrect memory management in the libgssapi_krb5 library might result in denial of service or potential execution of arbitrary code (CVE-2014-5352)
Comment 4 Janek Walkenhorst univentionstaff 2015-03-20 19:21:41 CET
Tests (i386): OK
Advisory: 2015-03-20-krb5.yaml
Comment 5 Moritz Muehlenhoff univentionstaff 2015-03-23 12:21:46 CET
The patch relax-build-deps.patch is no longer applied in the updated package.

Also, please update the YAML file: The CVE IDs which don't affect UCS (since we use Heimdal KDC/kadmin) should be listed separately with a note that these components are not used in UCS.
Comment 6 Janek Walkenhorst univentionstaff 2015-03-23 18:20:02 CET
(In reply to Moritz Muehlenhoff from comment #5)
> The patch relax-build-deps.patch is no longer applied in the updated package.
Fixed.
Tests (i386): OK

> Also, please update the YAML file: The CVE IDs which don't affect UCS (since
> we use Heimdal KDC/kadmin) should be listed separately with a note that
> these components are not used in UCS.
Fixed.
Comment 7 Moritz Muehlenhoff univentionstaff 2015-03-25 08:15:40 CET
Ok, looks good.
Comment 8 Janek Walkenhorst univentionstaff 2015-03-25 14:03:28 CET
<http://errata.univention.de/ucs/3.2/302.html>