krb5: kadmind invalid pointer free

Related Vulnerabilities: CVE-2011-0284   CVE-2010-4022   CVE-2011-0281   CVE-2011-0282  

Debian Bug report logs - #622681
krb5: kadmind invalid pointer free

version graph

Reported by: Michael Gilbert <michael.s.gilbert@gmail.com>

Date: Wed, 13 Apr 2011 19:21:01 UTC

Severity: important

Tags: confirmed, fixed-upstream, security, upstream

Merged with 621726

Found in version krb5/1.8.3+dfsg-4

Fixed in versions krb5/1.9.1+dfsg-1, krb5/1.8.3+dfsg-4squeeze1

Done: Sam Hartman <hartmans@debian.org>

Bug is archived. No further changes may be made.

Forwarded to http://krbdev.mit.edu/rt/Ticket/Display.html?id=6899

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Sam Hartman <hartmans@debian.org>:
Bug#622681; Package krb5. (Wed, 13 Apr 2011 19:21:04 GMT) (full text, mbox, link).


Acknowledgement sent to Michael Gilbert <michael.s.gilbert@gmail.com>:
New Bug report received and forwarded. Copy sent to Sam Hartman <hartmans@debian.org>. (Wed, 13 Apr 2011 19:21:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Michael Gilbert <michael.s.gilbert@gmail.com>
To: submit@bugs.debian.org
Subject: krb5: kadmind invalid pointer free
Date: Wed, 13 Apr 2011 15:20:16 -0400
package: krb5
version: 1.9+dfsg-1
severity: serious
tags: security

another advisory has been issued for kerberos:
http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-004.txt

best wishes,
mike




Set Bug forwarded-to-address to 'http://krbdev.mit.edu/rt/Ticket/Display.html?id=6899'. Request was from Tom Yu <tlyu@MIT.EDU> to control@bugs.debian.org. (Wed, 13 Apr 2011 19:39:14 GMT) (full text, mbox, link).


Severity set to 'important' from 'serious' Request was from Tom Yu <tlyu@MIT.EDU> to control@bugs.debian.org. (Wed, 13 Apr 2011 19:39:15 GMT) (full text, mbox, link).


Bug reassigned from package 'krb5' to 'krb5-admin-server'. Request was from Tom Yu <tlyu@MIT.EDU> to control@bugs.debian.org. (Wed, 13 Apr 2011 19:39:15 GMT) (full text, mbox, link).


Bug No longer marked as found in versions 1.9+dfsg-1. Request was from Tom Yu <tlyu@MIT.EDU> to control@bugs.debian.org. (Wed, 13 Apr 2011 19:39:16 GMT) (full text, mbox, link).


Merged 621726 622681. Request was from Tom Yu <tlyu@MIT.EDU> to control@bugs.debian.org. (Wed, 13 Apr 2011 19:39:18 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Sam Hartman <hartmans@debian.org>:
Bug#622681; Package krb5-admin-server. (Wed, 13 Apr 2011 19:45:06 GMT) (full text, mbox, link).


Acknowledgement sent to Tom Yu <tlyu@MIT.EDU>:
Extra info received and forwarded to list. Copy sent to Sam Hartman <hartmans@debian.org>. (Wed, 13 Apr 2011 19:45:06 GMT) (full text, mbox, link).


Message #20 received at 622681@bugs.debian.org (full text, mbox, reply):

From: Tom Yu <tlyu@MIT.EDU>
To: Michael Gilbert <michael.s.gilbert@gmail.com>
Cc: 622681@bugs.debian.org, control@bugs.debian.org
Subject: Re: Bug#622681: krb5: kadmind invalid pointer free
Date: Wed, 13 Apr 2011 15:37:51 -0400
forwarded 622681 http://krbdev.mit.edu/rt/Ticket/Display.html?id=6899
severity 622681 important
reassign 622681 krb5-admin-server
merge 622681 621726
thanks

Merging duplicate; the vulnerability was initially reported to Debian.




Added tag(s) pending. Request was from Sam Hartman <hartmans@debian.org> to control@bugs.debian.org. (Thu, 02 Jun 2011 15:09:04 GMT) (full text, mbox, link).


Reply sent to Sam Hartman <hartmans@debian.org>:
You have taken responsibility. (Fri, 03 Jun 2011 22:21:27 GMT) (full text, mbox, link).


Notification sent to Michael Gilbert <michael.s.gilbert@gmail.com>:
Bug acknowledged by developer. (Fri, 03 Jun 2011 22:21:27 GMT) (full text, mbox, link).


Message #27 received at 622681-close@bugs.debian.org (full text, mbox, reply):

From: Sam Hartman <hartmans@debian.org>
To: 622681-close@bugs.debian.org
Subject: Bug#622681: fixed in krb5 1.9.1+dfsg-1
Date: Fri, 03 Jun 2011 22:18:36 +0000
Source: krb5
Source-Version: 1.9.1+dfsg-1

We believe that the bug you reported is fixed in the latest version of
krb5, which is due to be installed in the Debian FTP archive:

krb5-admin-server_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/krb5-admin-server_1.9.1+dfsg-1_amd64.deb
krb5-doc_1.9.1+dfsg-1_all.deb
  to main/k/krb5/krb5-doc_1.9.1+dfsg-1_all.deb
krb5-gss-samples_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/krb5-gss-samples_1.9.1+dfsg-1_amd64.deb
krb5-kdc-ldap_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/krb5-kdc-ldap_1.9.1+dfsg-1_amd64.deb
krb5-kdc_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/krb5-kdc_1.9.1+dfsg-1_amd64.deb
krb5-multidev_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/krb5-multidev_1.9.1+dfsg-1_amd64.deb
krb5-pkinit_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/krb5-pkinit_1.9.1+dfsg-1_amd64.deb
krb5-user_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/krb5-user_1.9.1+dfsg-1_amd64.deb
krb5_1.9.1+dfsg-1.diff.gz
  to main/k/krb5/krb5_1.9.1+dfsg-1.diff.gz
krb5_1.9.1+dfsg-1.dsc
  to main/k/krb5/krb5_1.9.1+dfsg-1.dsc
krb5_1.9.1+dfsg.orig.tar.gz
  to main/k/krb5/krb5_1.9.1+dfsg.orig.tar.gz
libgssapi-krb5-2_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/libgssapi-krb5-2_1.9.1+dfsg-1_amd64.deb
libgssrpc4_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/libgssrpc4_1.9.1+dfsg-1_amd64.deb
libk5crypto3_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/libk5crypto3_1.9.1+dfsg-1_amd64.deb
libkadm5clnt-mit8_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/libkadm5clnt-mit8_1.9.1+dfsg-1_amd64.deb
libkadm5srv-mit8_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/libkadm5srv-mit8_1.9.1+dfsg-1_amd64.deb
libkdb5-5_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/libkdb5-5_1.9.1+dfsg-1_amd64.deb
libkrb5-3_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/libkrb5-3_1.9.1+dfsg-1_amd64.deb
libkrb5-dbg_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/libkrb5-dbg_1.9.1+dfsg-1_amd64.deb
libkrb5-dev_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/libkrb5-dev_1.9.1+dfsg-1_amd64.deb
libkrb53_1.9.1+dfsg-1_all.deb
  to main/k/krb5/libkrb53_1.9.1+dfsg-1_all.deb
libkrb5support0_1.9.1+dfsg-1_amd64.deb
  to main/k/krb5/libkrb5support0_1.9.1+dfsg-1_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 622681@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sam Hartman <hartmans@debian.org> (supplier of updated krb5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 02 Jun 2011 10:57:10 -0400
Source: krb5
Binary: krb5-user krb5-kdc krb5-kdc-ldap krb5-admin-server krb5-multidev libkrb5-dev libkrb5-dbg krb5-pkinit krb5-doc libkrb5-3 libgssapi-krb5-2 libgssrpc4 libkadm5srv-mit8 libkadm5clnt-mit8 libk5crypto3 libkdb5-5 libkrb5support0 krb5-gss-samples libkrb53
Architecture: source all amd64
Version: 1.9.1+dfsg-1
Distribution: unstable
Urgency: low
Maintainer: Sam Hartman <hartmans@debian.org>
Changed-By: Sam Hartman <hartmans@debian.org>
Description: 
 krb5-admin-server - MIT Kerberos master server (kadmind)
 krb5-doc   - Documentation for MIT Kerberos
 krb5-gss-samples - MIT Kerberos GSS Sample applications
 krb5-kdc   - MIT Kerberos key server (KDC)
 krb5-kdc-ldap - MIT Kerberos key server (KDC) LDAP plugin
 krb5-multidev - Development files for MIT Kerberos without Heimdal conflict
 krb5-pkinit - PKINIT plugin for MIT Kerberos
 krb5-user  - Basic programs to authenticate using MIT Kerberos
 libgssapi-krb5-2 - MIT Kerberos runtime libraries - krb5 GSS-API Mechanism
 libgssrpc4 - MIT Kerberos runtime libraries - GSS enabled ONCRPC
 libk5crypto3 - MIT Kerberos runtime libraries - Crypto Library
 libkadm5clnt-mit8 - MIT Kerberos runtime libraries - Administration Clients
 libkadm5srv-mit8 - MIT Kerberos runtime libraries - KDC and Admin Server
 libkdb5-5  - MIT Kerberos runtime libraries - Kerberos database
 libkrb5-3  - MIT Kerberos runtime libraries
 libkrb5-dbg - Debugging files for MIT Kerberos
 libkrb5-dev - Headers and development libraries for MIT Kerberos
 libkrb53   - transitional package for MIT Kerberos libraries
 libkrb5support0 - MIT Kerberos runtime libraries - Support library
Closes: 622681 624173 626530
Changes: 
 krb5 (1.9.1+dfsg-1) unstable; urgency=low
 .
   * New upstream version
   * Fix g_make_token_header when no token type is passed
   * Support absolute paths for GSS-API mechanisms
   * Add gss_authorize_localname, gss_userok,  gss_pname_to_uid
   * Fix gss_acquire_cred handling with empty mech set; fix
     accept_sec_context handling in this case too
   * Permit importing anonymous name with empty buffer
       * New Translations:
     - Dutch: Thanks  Vincent Zweije, Closes: #624173
     - Danish, Thanks  Joe Dalton, Closes: #626530
   * Fix kadmin free of null pointer on change password, Closes: #622681
Checksums-Sha1: 
 0fa0ba6ec64deadb463acd095154cf7e4edd98ab 1596 krb5_1.9.1+dfsg-1.dsc
 9dfb77239bcbecf461c9a691f7de40f325e0be3c 11803252 krb5_1.9.1+dfsg.orig.tar.gz
 fa7404a4f414987368495e2b52fe77ddffd4cac1 108948 krb5_1.9.1+dfsg-1.diff.gz
 145d66b98b63784dff42eca0b72e7988c8b285f7 2359944 krb5-doc_1.9.1+dfsg-1_all.deb
 6a9e7d26a662e393f07210ce49f17114cd6dd7b8 1413796 libkrb53_1.9.1+dfsg-1_all.deb
 35f85f1ddb76fa425604ef55aaa02f960fe52391 140116 krb5-user_1.9.1+dfsg-1_amd64.deb
 151652d53c7e54e33290844fe30291b02d3c4699 215536 krb5-kdc_1.9.1+dfsg-1_amd64.deb
 efa9406c83344b9f4a5580da7ec4f1582d435ed9 117072 krb5-kdc-ldap_1.9.1+dfsg-1_amd64.deb
 abef1f052cebb6b99057e7abc5cce4fb9d20c000 114258 krb5-admin-server_1.9.1+dfsg-1_amd64.deb
 b533ba53990345f0e11f598d17d827ce4778424e 114778 krb5-multidev_1.9.1+dfsg-1_amd64.deb
 9c77837d0e2b6f86fa115b291d7b7f578b246b1f 38232 libkrb5-dev_1.9.1+dfsg-1_amd64.deb
 d76bf51bb7bbb9fdcbb79184b0ac58aab273ba3b 1751352 libkrb5-dbg_1.9.1+dfsg-1_amd64.deb
 eee1c2cf835e4f47e77b1b74f803152d8bda6867 78766 krb5-pkinit_1.9.1+dfsg-1_amd64.deb
 f732ffc3d2c97d87442b5f916a0047105aa20232 381100 libkrb5-3_1.9.1+dfsg-1_amd64.deb
 47ff61bb39030f9b5ce47aef91b88aa378524857 146764 libgssapi-krb5-2_1.9.1+dfsg-1_amd64.deb
 35f951875de3d1c1a8c57bb516b2ab3015ef7530 85104 libgssrpc4_1.9.1+dfsg-1_amd64.deb
 4a06c7ae73d707d9649210cc9a031dcb850ae5aa 80836 libkadm5srv-mit8_1.9.1+dfsg-1_amd64.deb
 504157e6b993c10efcd159dd7b8365cab461de93 64716 libkadm5clnt-mit8_1.9.1+dfsg-1_amd64.deb
 a071090b9c204a5337551b4bfa57f0b06fe8e43a 110926 libk5crypto3_1.9.1+dfsg-1_amd64.deb
 0a52bc3e3b10f79985577ec0877bf6bab2a0ab21 62778 libkdb5-5_1.9.1+dfsg-1_amd64.deb
 6cd9fad32b7430066ddf9c34a9b37453379ddbbd 46870 libkrb5support0_1.9.1+dfsg-1_amd64.deb
 a6d359c85f7fffdd9d37abcb45b2ef05d6a3c6ee 50168 krb5-gss-samples_1.9.1+dfsg-1_amd64.deb
Checksums-Sha256: 
 8618bb2581d4c73e6d44621d8b6ae8629f874c82ad5c9cb578fb7791da894613 1596 krb5_1.9.1+dfsg-1.dsc
 d1879fa647568f34a56eca26226d2555af726ac85c30350c43c9beae6b091aa7 11803252 krb5_1.9.1+dfsg.orig.tar.gz
 b454428e0680a8b624f85842edf886db62c8e74100cd78c367296409c376f8d0 108948 krb5_1.9.1+dfsg-1.diff.gz
 f811da48551a0bab80fea1dd507033e5ab4ef7b16fa019b6b9de86d243211992 2359944 krb5-doc_1.9.1+dfsg-1_all.deb
 96badfa4ce724f6f809e4c1170c40cc9b67acd4b02aca5ca9d9fbee369ddda57 1413796 libkrb53_1.9.1+dfsg-1_all.deb
 55b4d35c5458070db127b6b0e9c23cf369afb12e07761bbf465ee2a62987b89e 140116 krb5-user_1.9.1+dfsg-1_amd64.deb
 bdcfa20c5e94dae7d2c0bd5011dfd312779e5c0f87532667d64e68c50fc785c9 215536 krb5-kdc_1.9.1+dfsg-1_amd64.deb
 89ccdf097ce7480972999858ce0e2d62c3a1182417aca40b26215df5895d7f61 117072 krb5-kdc-ldap_1.9.1+dfsg-1_amd64.deb
 edc76162062f286269e2270d412fe405472fe9a14d7f573bad277be0745c0f60 114258 krb5-admin-server_1.9.1+dfsg-1_amd64.deb
 b5fe0a98cbab21365d257610b3fe7aabe267bbf4a32028a56491fa6f4418ab94 114778 krb5-multidev_1.9.1+dfsg-1_amd64.deb
 b503b7daf72ab7f91d09183e89a54e1552be659c2c5409fac30708ede751138f 38232 libkrb5-dev_1.9.1+dfsg-1_amd64.deb
 5a5ef36f62cf3b514ec146ac567b7577baf080f5f78f38a4794326d87f60628f 1751352 libkrb5-dbg_1.9.1+dfsg-1_amd64.deb
 6283bde07368602fed5d7f24d994ddc040ac58ec9b82102c578166f1943679b7 78766 krb5-pkinit_1.9.1+dfsg-1_amd64.deb
 c800cd644141954b36a589e1e42d9846399c978ec5ff2c85f1efa2d900c6807c 381100 libkrb5-3_1.9.1+dfsg-1_amd64.deb
 22f0a36a1cf51c57356edf7f8352a54615620a5dd0f39dfb7c86a437037751c4 146764 libgssapi-krb5-2_1.9.1+dfsg-1_amd64.deb
 1243b8c958919f64ac21d3a18502b591af6904c44f3c247caee0c5e68b149d3f 85104 libgssrpc4_1.9.1+dfsg-1_amd64.deb
 1591d37e19bbc6fcd855288e7c4404658630fdc2609d739a2b04a2585e3f5ba5 80836 libkadm5srv-mit8_1.9.1+dfsg-1_amd64.deb
 e98c7a288ad530d2b0adcf1d25ff70a467db22bf54ac42da3ab585ff0241d3e7 64716 libkadm5clnt-mit8_1.9.1+dfsg-1_amd64.deb
 b4af4cf27277b159c84f02705b744b08cd7fe873155e99839341d5502cd7624b 110926 libk5crypto3_1.9.1+dfsg-1_amd64.deb
 431f9a7f785c0208a022149f2416dc2d2104c91a24bcc8485d50bcd513068451 62778 libkdb5-5_1.9.1+dfsg-1_amd64.deb
 d248342b74a76c88528a6e4ce1b972ea094603775801e616c4ac0a9228b4bc10 46870 libkrb5support0_1.9.1+dfsg-1_amd64.deb
 85d97c6ec5f10d7ff802100f9e17d7f0e2ce7e65badb3d855ecae3f22a3e0a73 50168 krb5-gss-samples_1.9.1+dfsg-1_amd64.deb
Files: 
 124363694dc4e19b343fcbcef3e56acc 1596 net standard krb5_1.9.1+dfsg-1.dsc
 559267dd21dd46f6ddb73ea1192f530a 11803252 net standard krb5_1.9.1+dfsg.orig.tar.gz
 ce2e299ef3c39699da9af1f0a4d24089 108948 net standard krb5_1.9.1+dfsg-1.diff.gz
 4762e78c09c6b78c1d335f926aaf82c1 2359944 doc optional krb5-doc_1.9.1+dfsg-1_all.deb
 3f8638902ed706156fd0a9a794c7cf91 1413796 oldlibs extra libkrb53_1.9.1+dfsg-1_all.deb
 0c2152fddbd6e90b182b890fcccb248e 140116 net optional krb5-user_1.9.1+dfsg-1_amd64.deb
 86cd070963e50abecb2d840e3e2a4987 215536 net optional krb5-kdc_1.9.1+dfsg-1_amd64.deb
 1a47a1ad5b36716d00ed19b85f9d3a1d 117072 net extra krb5-kdc-ldap_1.9.1+dfsg-1_amd64.deb
 abc2129d0d12c940efb1326e9d31f413 114258 net optional krb5-admin-server_1.9.1+dfsg-1_amd64.deb
 9356d7d8d9985480bd4ce91f62e57eb2 114778 libdevel optional krb5-multidev_1.9.1+dfsg-1_amd64.deb
 2bb8cd2e5f6eb269c1ed58609bbe2ce4 38232 libdevel extra libkrb5-dev_1.9.1+dfsg-1_amd64.deb
 da24d9b63af1721a0dee861fa50f0d57 1751352 debug extra libkrb5-dbg_1.9.1+dfsg-1_amd64.deb
 38c79508c0b4af73a7829a44f86fd40c 78766 net extra krb5-pkinit_1.9.1+dfsg-1_amd64.deb
 56043b878522f4435e059cac001ffb09 381100 libs standard libkrb5-3_1.9.1+dfsg-1_amd64.deb
 fcc17204a93ea138f8c97011c7d333d9 146764 libs standard libgssapi-krb5-2_1.9.1+dfsg-1_amd64.deb
 2f1d0921f3ff4331286ba62c0821b639 85104 libs standard libgssrpc4_1.9.1+dfsg-1_amd64.deb
 0c96df140c6e4df017d3042231d5729d 80836 libs standard libkadm5srv-mit8_1.9.1+dfsg-1_amd64.deb
 3f219859da1c6704f3af999e8b94c33d 64716 libs standard libkadm5clnt-mit8_1.9.1+dfsg-1_amd64.deb
 59179b7048d12f7514f7156afb5c531f 110926 libs standard libk5crypto3_1.9.1+dfsg-1_amd64.deb
 3345408c822eecb7a0b8ec32243dc076 62778 libs standard libkdb5-5_1.9.1+dfsg-1_amd64.deb
 1779770702f6c438774506e4a6b4c9c9 46870 libs standard libkrb5support0_1.9.1+dfsg-1_amd64.deb
 e988d3987d1301f258057fa2eaafd3ec 50168 net extra krb5-gss-samples_1.9.1+dfsg-1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAk3nsEQACgkQ/I12czyGJg/BHwCfSUB9/TQC+q5vW/w002Ahtlwe
nKgAoLcZC0Q5HxENe+klMM6wgW1AFpxS
=bcRp
-----END PGP SIGNATURE-----





Reply sent to Sam Hartman <hartmans@debian.org>:
You have taken responsibility. (Fri, 03 Jun 2011 22:21:27 GMT) (full text, mbox, link).


Notification sent to Felipe Ortega <ortegaga@gmail.com>:
Bug acknowledged by developer. (Fri, 03 Jun 2011 22:21:28 GMT) (full text, mbox, link).


Reply sent to Sam Hartman <hartmans@debian.org>:
You have taken responsibility. (Wed, 08 Jun 2011 01:57:13 GMT) (full text, mbox, link).


Notification sent to Michael Gilbert <michael.s.gilbert@gmail.com>:
Bug acknowledged by developer. (Wed, 08 Jun 2011 01:57:13 GMT) (full text, mbox, link).


Message #37 received at 622681-close@bugs.debian.org (full text, mbox, reply):

From: Sam Hartman <hartmans@debian.org>
To: 622681-close@bugs.debian.org
Subject: Bug#622681: fixed in krb5 1.8.3+dfsg-4squeeze1
Date: Wed, 08 Jun 2011 01:54:38 +0000
Source: krb5
Source-Version: 1.8.3+dfsg-4squeeze1

We believe that the bug you reported is fixed in the latest version of
krb5, which is due to be installed in the Debian FTP archive:

krb5-admin-server_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/krb5-admin-server_1.8.3+dfsg-4squeeze1_amd64.deb
krb5-doc_1.8.3+dfsg-4squeeze1_all.deb
  to main/k/krb5/krb5-doc_1.8.3+dfsg-4squeeze1_all.deb
krb5-kdc-ldap_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/krb5-kdc-ldap_1.8.3+dfsg-4squeeze1_amd64.deb
krb5-kdc_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/krb5-kdc_1.8.3+dfsg-4squeeze1_amd64.deb
krb5-multidev_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/krb5-multidev_1.8.3+dfsg-4squeeze1_amd64.deb
krb5-pkinit_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/krb5-pkinit_1.8.3+dfsg-4squeeze1_amd64.deb
krb5-user_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/krb5-user_1.8.3+dfsg-4squeeze1_amd64.deb
krb5_1.8.3+dfsg-4squeeze1.diff.gz
  to main/k/krb5/krb5_1.8.3+dfsg-4squeeze1.diff.gz
krb5_1.8.3+dfsg-4squeeze1.dsc
  to main/k/krb5/krb5_1.8.3+dfsg-4squeeze1.dsc
libgssapi-krb5-2_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/libgssapi-krb5-2_1.8.3+dfsg-4squeeze1_amd64.deb
libgssrpc4_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/libgssrpc4_1.8.3+dfsg-4squeeze1_amd64.deb
libk5crypto3_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/libk5crypto3_1.8.3+dfsg-4squeeze1_amd64.deb
libkadm5clnt-mit7_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/libkadm5clnt-mit7_1.8.3+dfsg-4squeeze1_amd64.deb
libkadm5srv-mit7_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/libkadm5srv-mit7_1.8.3+dfsg-4squeeze1_amd64.deb
libkdb5-4_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/libkdb5-4_1.8.3+dfsg-4squeeze1_amd64.deb
libkrb5-3_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/libkrb5-3_1.8.3+dfsg-4squeeze1_amd64.deb
libkrb5-dbg_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/libkrb5-dbg_1.8.3+dfsg-4squeeze1_amd64.deb
libkrb5-dev_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/libkrb5-dev_1.8.3+dfsg-4squeeze1_amd64.deb
libkrb53_1.8.3+dfsg-4squeeze1_all.deb
  to main/k/krb5/libkrb53_1.8.3+dfsg-4squeeze1_all.deb
libkrb5support0_1.8.3+dfsg-4squeeze1_amd64.deb
  to main/k/krb5/libkrb5support0_1.8.3+dfsg-4squeeze1_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 622681@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sam Hartman <hartmans@debian.org> (supplier of updated krb5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 02 Jun 2011 13:14:03 -0400
Source: krb5
Binary: krb5-user krb5-kdc krb5-kdc-ldap krb5-admin-server krb5-multidev libkrb5-dev libkrb5-dbg krb5-pkinit krb5-doc libkrb5-3 libgssapi-krb5-2 libgssrpc4 libkadm5srv-mit7 libkadm5clnt-mit7 libk5crypto3 libkdb5-4 libkrb5support0 libkrb53
Architecture: source all amd64
Version: 1.8.3+dfsg-4squeeze1
Distribution: stable
Urgency: low
Maintainer: Sam Hartman <hartmans@debian.org>
Changed-By: Sam Hartman <hartmans@debian.org>
Description: 
 krb5-admin-server - MIT Kerberos master server (kadmind)
 krb5-doc   - Documentation for MIT Kerberos
 krb5-kdc   - MIT Kerberos key server (KDC)
 krb5-kdc-ldap - MIT Kerberos key server (KDC) LDAP plugin
 krb5-multidev - Development files for MIT Kerberos without Heimdal conflict
 krb5-pkinit - PKINIT plugin for MIT Kerberos
 krb5-user  - Basic programs to authenticate using MIT Kerberos
 libgssapi-krb5-2 - MIT Kerberos runtime libraries - krb5 GSS-API Mechanism
 libgssrpc4 - MIT Kerberos runtime libraries - GSS enabled ONCRPC
 libk5crypto3 - MIT Kerberos runtime libraries - Crypto Library
 libkadm5clnt-mit7 - MIT Kerberos runtime libraries - Administration Clients
 libkadm5srv-mit7 - MIT Kerberos runtime libraries - KDC and Admin Server
 libkdb5-4  - MIT Kerberos runtime libraries - Kerberos database
 libkrb5-3  - MIT Kerberos runtime libraries
 libkrb5-dbg - Debugging files for MIT Kerberos
 libkrb5-dev - Headers and development libraries for MIT Kerberos
 libkrb53   - transitional package for MIT Kerberos libraries
 libkrb5support0 - MIT Kerberos runtime libraries - Support library
Closes: 584282 611906 613487 616429 616728 618517 622681
Changes: 
 krb5 (1.8.3+dfsg-4squeeze1) stable; urgency=low
 .
   * Fix double free with pkinit on KDC, CVE-2011-0284, Closes: #618517
   * Updated Danish debconf translations, thanks  Joe Dalton, Closes:
     #584282
   * KDC/LDAP DOS    (CVE-2010-4022, CVE-2011-0281, and CVE-2011-0282,
     Closes: #613487
   * Fix delegation of credentials against Windows servers; significant
     interoperability issue, Closes: #611906
   * Set nt-srv-inst on TGS names to work against W2K8R2 KDCs, Closes:
     #616429
   * Don't fail authentication when PAC verification fails; support hmac-
     md5 checksums even for non-RC4 keys, Closes: #616728
   * Port fix to upstream ticket 6899: fix invalid free in kadmind change
     password case, Closes: #622681
Checksums-Sha1: 
 e365edbf5074a9ed77528bf9aade4a578207426b 1610 krb5_1.8.3+dfsg-4squeeze1.dsc
 b2b9bc3225d687180bf2bf208894380cba43740e 105919 krb5_1.8.3+dfsg-4squeeze1.diff.gz
 8e1403ed2baa677989a67245e73fe047038e3dd9 2253356 krb5-doc_1.8.3+dfsg-4squeeze1_all.deb
 c78dcadcb98ca098c3cc34e00124a17ed79906bb 1373520 libkrb53_1.8.3+dfsg-4squeeze1_all.deb
 85c3079d77351cad4a882721f9a4d8de5db00b76 139100 krb5-user_1.8.3+dfsg-4squeeze1_amd64.deb
 e591007dae060dd83629f778566964d07f758dc9 220522 krb5-kdc_1.8.3+dfsg-4squeeze1_amd64.deb
 f0896b03ee679836b53fd6698028e704e90f8a2c 118352 krb5-kdc-ldap_1.8.3+dfsg-4squeeze1_amd64.deb
 f72a4a3868aa95c5212e502e361d2ed7e483a55e 114526 krb5-admin-server_1.8.3+dfsg-4squeeze1_amd64.deb
 9f31d52b81a318949533b63619c717b0345ddda4 103340 krb5-multidev_1.8.3+dfsg-4squeeze1_amd64.deb
 16d904d6ff8c251a37f876e55efa5b6a1db6be48 37328 libkrb5-dev_1.8.3+dfsg-4squeeze1_amd64.deb
 b4705aa6dd50d79a5bf09c55c485b40aeb4f4d03 1629346 libkrb5-dbg_1.8.3+dfsg-4squeeze1_amd64.deb
 e9dd8001f67b7aff8c636343a768bda831180d4e 78164 krb5-pkinit_1.8.3+dfsg-4squeeze1_amd64.deb
 dae18c9ec215244325e5d14f481c51a553b4aa88 375018 libkrb5-3_1.8.3+dfsg-4squeeze1_amd64.deb
 543b742bf318ddd0cb19e5430c1d0f8c793c9759 130600 libgssapi-krb5-2_1.8.3+dfsg-4squeeze1_amd64.deb
 7c42ffc9038fe998996a0285ad66d5fabcfda097 84016 libgssrpc4_1.8.3+dfsg-4squeeze1_amd64.deb
 3edc3ebf11e5b268cb1189b9cdb9dd385a50e719 78568 libkadm5srv-mit7_1.8.3+dfsg-4squeeze1_amd64.deb
 9369b5921d3013ff2fb3147b7357281922399e7e 64094 libkadm5clnt-mit7_1.8.3+dfsg-4squeeze1_amd64.deb
 833545785266e85abf52916c519005f38c555c8d 106066 libk5crypto3_1.8.3+dfsg-4squeeze1_amd64.deb
 54ceac7a672753b55fee3a8c896d1d0d66d5a526 63570 libkdb5-4_1.8.3+dfsg-4squeeze1_amd64.deb
 328bfb823dae9ee5b6c34f2e34d5491a47fffe73 45810 libkrb5support0_1.8.3+dfsg-4squeeze1_amd64.deb
Checksums-Sha256: 
 cf491b4ffdd52f299298f79a7e296656f7a65eacd497f26609caabe06c58ad26 1610 krb5_1.8.3+dfsg-4squeeze1.dsc
 3278d5ded7dfa5a4241952303bece47daca68bb7c0316d3208d0cc8902d4131f 105919 krb5_1.8.3+dfsg-4squeeze1.diff.gz
 94fb3d1f70c871d77f124b49df3df9e4f3e3d1a23d58397b71efcb1051dad3a3 2253356 krb5-doc_1.8.3+dfsg-4squeeze1_all.deb
 2b11a858255cc66f5d34d7b324ad2cbbe2be2ee6d83b6aa2be7af87bbde28a67 1373520 libkrb53_1.8.3+dfsg-4squeeze1_all.deb
 f50b915a0114906c8e0cee9164885e34fe84c6be22aade1f1f5800dbe905198a 139100 krb5-user_1.8.3+dfsg-4squeeze1_amd64.deb
 869a6d04124095c94d19ea99dd5e7bbdb5399ade2a534ac881853c2e0bd157f5 220522 krb5-kdc_1.8.3+dfsg-4squeeze1_amd64.deb
 af705977cf71ddefd12aa5d2bb4b1223affd6c239109b6147885bed5d884420d 118352 krb5-kdc-ldap_1.8.3+dfsg-4squeeze1_amd64.deb
 7f8e378cbcd48973d3520b18d1def8dbf0329499a54dfc1504b8ae63d2f2fea4 114526 krb5-admin-server_1.8.3+dfsg-4squeeze1_amd64.deb
 8f6ea2aab9d82b5b644f0292f671ef3d37a8085ac91171b0ec0531bc4294e065 103340 krb5-multidev_1.8.3+dfsg-4squeeze1_amd64.deb
 4bfe70488aae25186cb960b1ea9676c24ccf9c618a7fa2d75af00cc7b3bdc12c 37328 libkrb5-dev_1.8.3+dfsg-4squeeze1_amd64.deb
 2c593aa9177933533d4c91539556a5eccf8c5d0d3bdaa559f3e911a463ae3563 1629346 libkrb5-dbg_1.8.3+dfsg-4squeeze1_amd64.deb
 b41948b59a8f8c5acf0cd4c7d253c67fa073d4864bee82da61edf2977ec833ff 78164 krb5-pkinit_1.8.3+dfsg-4squeeze1_amd64.deb
 f672866b2d9c1a6922236116a808600ac4b82543fb0379cc799311b8d3a6cc0f 375018 libkrb5-3_1.8.3+dfsg-4squeeze1_amd64.deb
 b5e4d2e33d84f718050a024bdd06b59df2297824b79e5c05052065a9524912a8 130600 libgssapi-krb5-2_1.8.3+dfsg-4squeeze1_amd64.deb
 67b66784852744578477724edea8e924e8faae81f2111777753fa6578870cf87 84016 libgssrpc4_1.8.3+dfsg-4squeeze1_amd64.deb
 48d2406537b1d6027cc1fd9580c4ad384c51ea436fb5678516d6ee68ffa9927b 78568 libkadm5srv-mit7_1.8.3+dfsg-4squeeze1_amd64.deb
 5050abac0958afae13fc5d300512b0d684f9b5895e292f39e4a87ac3320cb12e 64094 libkadm5clnt-mit7_1.8.3+dfsg-4squeeze1_amd64.deb
 d5410484c7d7984e3c8a34af3d80beb95d01e366589df676cce25eb97d965003 106066 libk5crypto3_1.8.3+dfsg-4squeeze1_amd64.deb
 df42dd9f6a02cd5d5dfbb8d233af1b1e2a7d7d03a00ed49f4eb347b31f42d4b2 63570 libkdb5-4_1.8.3+dfsg-4squeeze1_amd64.deb
 4e98655e36d6bfa1768e5f85e0632fc9e9f714ca0c6d65311b579150fcddd34e 45810 libkrb5support0_1.8.3+dfsg-4squeeze1_amd64.deb
Files: 
 3c431c531b8426f1d48ad8f419209f57 1610 net standard krb5_1.8.3+dfsg-4squeeze1.dsc
 a2019a80103362ddd8044f42d9b8f3bf 105919 net standard krb5_1.8.3+dfsg-4squeeze1.diff.gz
 b0137d5452c726271dbd306f72fd2130 2253356 doc optional krb5-doc_1.8.3+dfsg-4squeeze1_all.deb
 69af33c86f32004ca9dc4d0f7f19c5bc 1373520 oldlibs extra libkrb53_1.8.3+dfsg-4squeeze1_all.deb
 604c112e735ce804494821b759e32e23 139100 net optional krb5-user_1.8.3+dfsg-4squeeze1_amd64.deb
 eb447f3979c7704f8f24e0f67acdf6a9 220522 net optional krb5-kdc_1.8.3+dfsg-4squeeze1_amd64.deb
 fb39a30a60465c8edf281665c1ba326d 118352 net extra krb5-kdc-ldap_1.8.3+dfsg-4squeeze1_amd64.deb
 cd51b343d0c5855208564bab19591e6d 114526 net optional krb5-admin-server_1.8.3+dfsg-4squeeze1_amd64.deb
 ce0e187d8aed0f9e7750fb68778d972f 103340 libdevel optional krb5-multidev_1.8.3+dfsg-4squeeze1_amd64.deb
 27dd07656be90d57062121c5f734bd93 37328 libdevel extra libkrb5-dev_1.8.3+dfsg-4squeeze1_amd64.deb
 4cfeabf8ff952b07733caa8585919546 1629346 debug extra libkrb5-dbg_1.8.3+dfsg-4squeeze1_amd64.deb
 41c74ae3e7eca73e62ecf17dd7226aab 78164 net extra krb5-pkinit_1.8.3+dfsg-4squeeze1_amd64.deb
 6a7c2b8db72b3032c58410a685642d8e 375018 libs standard libkrb5-3_1.8.3+dfsg-4squeeze1_amd64.deb
 77a2fab35ab1bf717b267818331e0f8c 130600 libs standard libgssapi-krb5-2_1.8.3+dfsg-4squeeze1_amd64.deb
 7625d2f7fe3cfb3379404fb1f7a91ebb 84016 libs standard libgssrpc4_1.8.3+dfsg-4squeeze1_amd64.deb
 b47cd3b359404b81ff6598b4772eff23 78568 libs standard libkadm5srv-mit7_1.8.3+dfsg-4squeeze1_amd64.deb
 471bb350eb5c54b26fa81a55f5c3eb3f 64094 libs standard libkadm5clnt-mit7_1.8.3+dfsg-4squeeze1_amd64.deb
 1c1e3be738a4c36fc00966fc2645eebb 106066 libs standard libk5crypto3_1.8.3+dfsg-4squeeze1_amd64.deb
 70a8bbeeedc04351c4fcf23ddd08e13b 63570 libs standard libkdb5-4_1.8.3+dfsg-4squeeze1_amd64.deb
 f07a690fa90966096f163cff34f8992e 45810 libs standard libkrb5support0_1.8.3+dfsg-4squeeze1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAk3nzikACgkQ/I12czyGJg/ZaQCfakbKebrYpsv64ThAfNe659X3
V00AoM+FqyZYJZcPYEgZ6uNfZE8q0KM3
=AuUz
-----END PGP SIGNATURE-----





Reply sent to Sam Hartman <hartmans@debian.org>:
You have taken responsibility. (Wed, 08 Jun 2011 01:57:14 GMT) (full text, mbox, link).


Notification sent to Felipe Ortega <ortegaga@gmail.com>:
Bug acknowledged by developer. (Wed, 08 Jun 2011 01:57:14 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 12 Jul 2011 07:36:19 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 17:23:15 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.