Bug 3958

Summary: krb5 (cauldron) needs a patch for CVE-2011-1530
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Mageia Bug Squad <bugsquad>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Normal CC: arnaud.patard, dmorganec, guillomovitch, mageia, saispo
Version: Cauldron   
Target Milestone: ---   
Hardware: i586   
OS: Linux   
Whiteboard:
Source RPM: krb5-1.9.2-1.mga2.src.rpm CVE:
Status comment:

Description David Walser 2011-12-31 00:17:04 CET
The patch is here:
http://web.mit.edu/kerberos/advisories/2011-007-patch.txt

Mandriva's advisory from December 12:
http://lists.mandriva.com/security-announce/2011-12/msg00006.php
Manuel Hiebel 2011-12-31 13:16:11 CET

CC: (none) => arnaud.patard, guillomovitch, mageia, saispo
Summary: krb5 needs a patch for CVE-2011-1530 => krb5 (cauldron) needs a patch for CVE-2011-1530

Comment 1 D Morgan 2012-01-02 03:27:57 CET
"In releases krb5-1.9 and later, the KDC can crash due to a null
pointer dereference in code that handles TGS (Ticket Granting Service)
requests.  The trigger condition is trivial to produce using
unmodified client software, but requires the ability to authenticate
as a principal in the KDC's realm."

In mageia 1 we have only a 1.8.3 version so we are not affected

Status: NEW => RESOLVED
CC: (none) => dmorganec
Resolution: (none) => FIXED

Comment 2 David Walser 2012-01-02 03:30:09 CET
This bug report is for Cauldron.

Status: RESOLVED => REOPENED
Resolution: FIXED => (none)

Comment 3 D Morgan 2012-01-02 03:40:30 CET
just pushed for cauldron sorry

Status: REOPENED => RESOLVED
Resolution: (none) => FIXED