[CLSA-2024:1726840907] krb5: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2024-09-20 14:05:33 UTC
Description:
- CVE-2024-37370: prevent modification of Extra Count field in GSS krb5 wrap token to avoid appearing truncated to application - CVE-2024-37371: fix invalid memory reads during GSS message token handling
Updated packages:
  • krb5-devel-1.15.1-55.el7_9.tuxcare.els1.i686.rpm
    sha:63e772536988063d2b45ea00a0b9f0c525e84d3f5a34418ffaebcfdb14c9e8f3
  • krb5-devel-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:5f8fe636de3de015de357b1cc053e6b1ca1b7910751bb0d09a70dbec95f8f2ba
  • krb5-libs-1.15.1-55.el7_9.tuxcare.els1.i686.rpm
    sha:4587eda79d19a6a91378a3a45df616f7e3c94c554d28c1f03fb8b4728fcf4251
  • krb5-libs-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:db466ad7a32237ae7d651a9f99c441956e9b52d14f83ae28e38435b65fb8d5ff
  • krb5-pkinit-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:70b69adc25fffd68ace6a7852bd6d78ac18518143d7a1a80554b82d07132b015
  • krb5-server-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:e53c1c78f3d4f9f0d59da8f3277d9ceac3270680567c313c4b423ca247c63b4c
  • krb5-server-ldap-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:e0c199eb6c77026b5adc28e09dd5d9d726a2ec84855f8c6bcedc7570802f2095
  • krb5-workstation-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:c1777177b43028ac82bae70f65f69a3c3b60485be94cb5e7f977d214c6a785ba
  • libkadm5-1.15.1-55.el7_9.tuxcare.els1.i686.rpm
    sha:039244923ab4e5cf5cac98e6cba5fc45b12d78535643959fd1e71b1e0b9e8fba
  • libkadm5-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:c2f7b6d8c77abf8e8ac1e7fb8581f15f8a02e2e7c0c4f3aa32808738a5f05cb1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.