Files
meta-openembedded/meta-oe/recipes-connectivity
Wenzong Fan 6c1b51eff1 krb5: fix CVE-2015-2698
The iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c
in MIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly
accesses a certain pointer, which allows remote authenticated users
to cause a denial of service (memory corruption) or possibly have
unspecified other impact by interacting with an application that calls
the gss_export_sec_context function. NOTE: this vulnerability exists
because of an incorrect fix for CVE-2015-2696.

Backport upstream commit to fix it:
https://github.com/krb5/krb5/commit/3db8dfec1ef50ddd78d6ba9503185995876a39fd

Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com>
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-12-20 14:11:57 -08:00
..
2014-07-15 15:02:28 +02:00
2015-12-20 14:11:57 -08:00
2015-07-16 21:09:03 +02:00
2015-02-19 10:09:57 +01:00
2014-07-15 14:56:55 +02:00
2015-07-16 21:09:06 +02:00
2015-01-08 11:58:43 +01:00
2014-07-22 00:01:58 +02:00
2015-05-28 10:35:17 +02:00
2014-11-28 13:41:01 +01:00
2013-07-30 11:17:11 +02:00
2015-05-11 10:57:11 +02:00
2015-08-31 19:51:38 +02:00