Files
meta-openembedded/meta-oe/recipes-connectivity
Soumya Sambu 39d15cf5cb krb5: Fix CVE-2023-36054
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2
and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote
authenticated user can trigger a kadmind crash. This occurs because
_xdr_kadm5_principal_ent_rec does not validate the relationship
between n_key_data and the key_data array count.

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-36054

Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2023-09-04 11:57:41 -04:00
..
2021-08-03 10:21:25 -07:00
2022-01-25 10:56:04 -08:00
2022-03-29 08:28:38 -07:00
2023-09-04 11:57:41 -04:00
2022-03-31 11:54:44 -07:00
2022-03-03 23:07:50 -08:00
2022-03-03 23:07:50 -08:00
2022-07-21 07:17:15 -07:00
2023-08-03 16:50:52 -04:00