-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 21 Jul 2004 16:55:05 -0400 Source: krb5 Binary: krb5-kdc krb5-doc krb5-rsh-server libkrb5-dev libkrb53 krb5-ftpd krb5-clients krb5-user libkadm55 krb5-telnetd krb5-admin-server Architecture: source alpha all Version: 1.2.4-5woody6 Distribution: stable-security Urgency: high Maintainer: Martin Schulze Changed-By: Sam Hartman Description: krb5-admin-server - Mit Kerberos master server (kadmind) krb5-clients - Secure replacements for ftp, telnet and rsh using MIT Kerberos krb5-doc - Documentation for krb5 krb5-ftpd - Secure FTP server supporting MIT Kerberos krb5-kdc - Mit Kerberos key server (KDC) krb5-rsh-server - Secure replacements for rshd and rlogind using MIT Kerberos krb5-telnetd - Secure telnet server supporting MIT Kerberos krb5-user - Basic programs to authenticate using MIT Kerberos libkadm55 - MIT Kerberos administration runtime libraries libkrb5-dev - Headers and development libraries for MIT Kerberos libkrb53 - MIT Kerberos runtime libraries Changes: krb5 (1.2.4-5woody6) stable-security; urgency=high . * KDC and clients double-free on error conditions (CAN-2004-0642) * krb5_rd_cred() double-frees on error conditions (CAN-2004-0643) * ASN.1 decoder in MIT Kerberos 5 releases krb5-1.3.4 and earlier allows unauthenticated remote attackers to induce infinite loop, causing denial of service, including in KDC code (CAN-2004-0644) * Update double free patch to include an additional rd_cred case Files: ac9c3b7f0d3e5187c7e13cb4c3a4dc8a 750 net optional krb5_1.2.4-5woody6.dsc 913379c70d82a8229383a36cf0b4d77f 81598 net optional krb5_1.2.4-5woody6.diff.gz d1fe8d1575287b2afd7a45c0dbae0ef5 512766 net optional krb5-doc_1.2.4-5woody6_all.deb 0d29998a8afed416a4bd3c5dee6396a9 83608 libs optional libkadm55_1.2.4-5woody6_alpha.deb 149bebb9742b8d1647209a5c30d03bdb 367242 libs optional libkrb53_1.2.4-5woody6_alpha.deb 3e96a9770f5219d8c674f8650414be55 207342 net optional krb5-user_1.2.4-5woody6_alpha.deb b4f44f5b653d3df770eea062bdeb2498 217370 net optional krb5-clients_1.2.4-5woody6_alpha.deb a3e9dce7bc89de97d5a6c9a035b7d909 76244 net optional krb5-rsh-server_1.2.4-5woody6_alpha.deb a5d09242a0d5954214bda59f338d2b99 62880 net extra krb5-ftpd_1.2.4-5woody6_alpha.deb b78c904ed4dff722d2752a726b30b262 58906 net extra krb5-telnetd_1.2.4-5woody6_alpha.deb 489657290fa5204f08ec988cf8a0560c 251970 net optional krb5-kdc_1.2.4-5woody6_alpha.deb 8603d10da2d300e45ff67bd7cac1a5d6 253608 net optional krb5-admin-server_1.2.4-5woody6_alpha.deb 9557407fc033ddd591e78df0ced731f2 633124 devel optional libkrb5-dev_1.2.4-5woody6_alpha.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iD8DBQFBHJ0DW5ql+IAeqTIRApAJAKCQ3nyBirgRF+xZu4CrFep/4CAIOgCeMem0 iHjVbSksfHwGJVAmz5nvpk8= =lp3y -----END PGP SIGNATURE-----