MGASA-2017-0256

Source
https://advisories.mageia.org/MGASA-2017-0256.html
Import Source
https://advisories.mageia.org/MGASA-2017-0256.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0256
Related
Published
2017-08-12T10:13:00Z
Modified
2017-08-12T09:56:08Z
Summary
Updated krb5 packages fix security vulnerability
Details

A denial of service flaw was found in MIT Kerberos krb5kdc service. An authenticated attacker could use this flaw to cause krb5kdc to exit with an assertion failure by making an invalid S4U2Self or S4U2Proxy request (CVE-2017-11368).

References
Credits

Affected packages

Mageia:6 / krb5

Package

Name
krb5
Purl
pkg:rpm/mageia/krb5?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.15.1-2.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / krb5

Package

Name
krb5
Purl
pkg:rpm/mageia/krb5?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.5-1.2.mga5

Ecosystem specific

{
    "section": "core"
}