SUSE-SU-2015:1897-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1897-1
SUSE-SU-2015:1897-1
Summary: Security update for krb5
Details: krb5 was updated to fix three security issues. These security issues were fixed: - CVE-2015-2695: Applications which call gss_inquire_context() on a partially-established SPNEGO context could have caused the GSS-API library to read from a pointer using the wrong type, generally causing a process crash. (bsc#952188). - CVE-2015-2696: Applications which call gss_inquire_context() on a partially-established IAKERB context could have caused the GSS-API library to read from a pointer using the wrong type, generally causing a process crash. (bsc#952189). - CVE-2015-2697: Incorrect string handling in build_principal_va can lead to DOS (bsc#952190).
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151897-1/, https://bugzilla.suse.com/948011, https://bugzilla.suse.com/952188, https://bugzilla.suse.com/952189, https://bugzilla.suse.com/952190, https://www.suse.com/security/cve/CVE-2015-2695, https://www.suse.com/security/cve/CVE-2015-2696, https://www.suse.com/security/cve/CVE-2015-2697
Affected packages
Package
Name: krb5
Purl: pkg:rpm/suse/krb5&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Affected ranges
Type: ECOSYSTEM
Events:
