SUSE-SU-2015:1276-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1276-1
SUSE-SU-2015:1276-1
Summary: Security update for krb5
Details: krb5 was updated to fix four security issues. These security issues were fixed: - CVE-2014-5353: NULL pointer dereference when using a ticket policy name as password name (bsc#910457). - CVE-2014-5354: NULL pointer dereference when using keyless entries (bsc#910458). - CVE-2014-5355: Denial of service in krb5_read_message (bsc#918595). - CVE-2015-2694: OTP and PKINIT kdcpreauth modules leading to requires_preauth bypass (bsc#928978).
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151276-1/, https://bugzilla.suse.com/910457, https://bugzilla.suse.com/910458, https://bugzilla.suse.com/918595, https://bugzilla.suse.com/928978, https://www.suse.com/security/cve/CVE-2014-5353, https://www.suse.com/security/cve/CVE-2014-5354, https://www.suse.com/security/cve/CVE-2014-5355, https://www.suse.com/security/cve/CVE-2015-2694
Affected packages
Package
Name: krb5
Purl: pkg:rpm/suse/krb5&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012
Affected ranges
Type: ECOSYSTEM
Events:
