MGASA-2015-0446
Dashboard / Vulnerabilities / MGASA-2015-0446
Summary: Updated krb5 packages fix CVE-2015-2698
Details: Updated krb5 packages fix security vulnerabilities: In any MIT krb5 release with the patches for CVE-2015-2696 applied, an application which calls gss_export_sec_context() may experience memory corruption if the context was established using the IAKERB mechanism. Historically, some vulnerabilities of this nature can be translated into remote code execution, though the necessary exploits must be tailored to the individual application and are usually quite complicated (CVE-2015-2698).
References: https://advisories.mageia.org/MGASA-2015-0446.html, https://bugs.mageia.org/show_bug.cgi?id=17116, http://advisories.mageia.org/MGASA-2015-0436.html, https://lists.fedoraproject.org/pipermail/package-announce/2015-November/171079.html
Affected packages
Package
Name: krb5
Purl: pkg:rpm/mageia/krb5?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
