-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 21 Jul 2004 16:55:05 -0400 Source: krb5 Binary: krb5-kdc krb5-doc krb5-rsh-server libkrb5-dev libkrb53 krb5-ftpd krb5-clients krb5-user libkadm55 krb5-telnetd krb5-admin-server Architecture: m68k Version: 1.2.4-5woody6 Distribution: stable-security Urgency: high Maintainer: Debian/m68k (q650) buildd Changed-By: Sam Hartman Description: krb5-admin-server - Mit Kerberos master server (kadmind) krb5-clients - Secure replacements for ftp, telnet and rsh using MIT Kerberos krb5-ftpd - Secure FTP server supporting MIT Kerberos krb5-kdc - Mit Kerberos key server (KDC) krb5-rsh-server - Secure replacements for rshd and rlogind using MIT Kerberos krb5-telnetd - Secure telnet server supporting MIT Kerberos krb5-user - Basic programs to authenticate using MIT Kerberos libkadm55 - MIT Kerberos administration runtime libraries libkrb5-dev - Headers and development libraries for MIT Kerberos libkrb53 - MIT Kerberos runtime libraries Changes: krb5 (1.2.4-5woody6) stable-security; urgency=high . * KDC and clients double-free on error conditions (CAN-2004-0642) * krb5_rd_cred() double-frees on error conditions (CAN-2004-0643) * ASN.1 decoder in MIT Kerberos 5 releases krb5-1.3.4 and earlier allows unauthenticated remote attackers to induce infinite loop, causing denial of service, including in KDC code (CAN-2004-0644) * Update double free patch to include an additional rd_cred case Files: 887174300de4016d12e07ef6b9daa8ef 69760 libs optional libkadm55_1.2.4-5woody6_m68k.deb e45a5c7dc4cb1212b217ad9ae0aed680 277046 libs optional libkrb53_1.2.4-5woody6_m68k.deb c28052612efd159617790a1aa3b0e76a 145966 net optional krb5-user_1.2.4-5woody6_m68k.deb df4087c48b4498a02952a8ef6eb8067b 144682 net optional krb5-clients_1.2.4-5woody6_m68k.deb ef970b995d8e45560e16f0c12a024aff 56838 net optional krb5-rsh-server_1.2.4-5woody6_m68k.deb c08e47ea2c8f4b343ec226fac2e80dac 44308 net extra krb5-ftpd_1.2.4-5woody6_m68k.deb 150196caa13aac7658f1329e75135891 44628 net extra krb5-telnetd_1.2.4-5woody6_m68k.deb 07539c1abc32983b08b7daf6a4f7cdd6 163902 net optional krb5-kdc_1.2.4-5woody6_m68k.deb 3b2e8e114f38e42a3ad3a00753885a92 164184 net optional krb5-admin-server_1.2.4-5woody6_m68k.deb b1839eee1df0f6ef404b05a749128ea8 408702 devel optional libkrb5-dev_1.2.4-5woody6_m68k.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iD8DBQFBHR2eW5ql+IAeqTIRAnjLAJ90mDArfimAC0GDX9zaC7AgEff7AwCeM3Ep 6ty/mGIX7YftELwwK3G1XlA= =i7JJ -----END PGP SIGNATURE-----