UbuntuUpdates.org

Package "krb5-otp"

Name: krb5-otp

Description:

OTP plugin for MIT Kerberos

Latest version: 1.21.3-3ubuntu0.2
Release: oracular (24.10)
Level: updates
Repository: universe
Head package: krb5
Homepage: https://web.mit.edu/kerberos/

Links


Download "krb5-otp"


Other versions of "krb5-otp" in Oracular

Repository Area Version
base universe 1.21.3-3
security universe 1.21.3-3ubuntu0.2

Changelog

Version: 1.21.3-3ubuntu0.2 2025-03-03 21:07:05 UTC

  krb5 (1.21.3-3ubuntu0.2) oracular-security; urgency=medium

  * SECURITY UPDATE: denial of service via two memory leaks
    - debian/patches/CVE-2024-26458.patch: fix two unlikely memory leaks in
      src/lib/gssapi/krb5/k5sealv3.c, src/lib/rpc/pmap_rmt.c.
    - CVE-2024-26458
    - CVE-2024-26461
  * SECURITY UPDATE: kadmind DoS via iprop log file
    - debian/patches/CVE-2025-24528.patch: prevent overflow when
      calculating ulog block size in src/lib/kdb/kdb_log.c.
    - CVE-2025-24528

 -- Marc Deslauriers <email address hidden> Tue, 25 Feb 2025 10:26:19 -0500

Source diff to previous version
CVE-2024-26458 Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
CVE-2024-26461 Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
CVE-2025-24528 Prevent overflow when calculating ulog block size

Version: 1.21.3-3ubuntu0.1 2025-02-05 09:07:11 UTC

  krb5 (1.21.3-3ubuntu0.1) oracular-security; urgency=medium

  * SECURITY UPDATE: Use of MD5-based message authentication over plaintext
    communications could lead to forgery attacks.
    - debian/patches/CVE-2024-3596.patch: Secure Response Authenticator
      by adding support for the Message-Authenticator attribute in non-EAP
      authentication methods.
    - CVE-2024-3596$
  * Update libk5crypto3 symbols: add k5_hmac_md5 symbol.

 -- Nicolas Campuzano Jimenez <email address hidden> Tue, 04 Feb 2025 10:56:13 -0500

CVE-2024-3596 RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject,



About   -   Send Feedback to @ubuntu_updates