[CLSA-2024:1726841437] krb5: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2024-09-20 14:10:41 UTC
Description:
- CVE-2024-37370: prevent modification of Extra Count field in GSS krb5 wrap token to avoid appearing truncated to application - CVE-2024-37371: fix invalid memory reads during GSS message token handling
Updated packages:
  • krb5-devel-1.15.1-55.el7_9.tuxcare.els1.i686.rpm
    sha:1ba18dc8fc6748aa5be87bca1919fb39d4ce42018cf2ac989a3d351cbdd51781
  • krb5-devel-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:7ce4ad000eebbf984dd060f5864f6faa473aabed80ca9a57afcad9840cf9eb9e
  • krb5-libs-1.15.1-55.el7_9.tuxcare.els1.i686.rpm
    sha:590aa62a795fdc4ae71de0eb174a1534cd81dfa45b64a3c80b8f2a02306b679e
  • krb5-libs-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:3a0cb9856cc6d3326c25eb8004c290aff43cd52b5fe9e9fab6ac43fec2bde0e4
  • krb5-pkinit-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:c50208ab2ed7972b7caf319f378d1d6022b6b080a4043ce50ab51bb9cf6a381b
  • krb5-server-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:762676f0e165e88a3460ad1764073ab09df485b7116b5206b90466fb676e0cd3
  • krb5-server-ldap-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:3b7d71809c48f26ddc7a44099e5f35e356a721e8118ba7b43cf5d66618e4140e
  • krb5-workstation-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:09727d955c5ffed3c1ee0b2afc266a5a3d968d9a2e97f102dfd77b174a42c387
  • libkadm5-1.15.1-55.el7_9.tuxcare.els1.i686.rpm
    sha:fb8bf69f92e3bfc95b50ed08e1da30096a93b9fc773655f29bd30585856191fd
  • libkadm5-1.15.1-55.el7_9.tuxcare.els1.x86_64.rpm
    sha:d18d8696de9abdc109c31f1d3acb39d83fc3999fe95b7e913f18fd0277cf3917
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.