UbuntuUpdates.org

Package "python-kerberos"

Name: python-kerberos

Description:

GSSAPI interface module for Python

Latest version: 1.1+svn10616-2ubuntu0.1
Release: trusty (14.04)
Level: security
Repository: universe
Head package: pykerberos

Links


Download "python-kerberos"


Other versions of "python-kerberos" in Trusty

Repository Area Version
base universe 1.1+svn10616-2
updates universe 1.1+svn10616-2ubuntu0.1

Changelog

Version: 1.1+svn10616-2ubuntu0.1 2018-02-06 18:06:39 UTC

  pykerberos (1.1+svn10616-2ubuntu0.1) trusty-security; urgency=medium

  * SECURITY UPDATE: The checkPassword function does not authenticate the
    KDC it attempts to communicate with (LP: #1716429)
    - Add-KDC-authenticity-verification-support-CVE-2015-3206.patch
      retrieved from xenial version (1.1.5-2build1).
    - CVE-2015-3206
    - debian/NEWS: add explanation of issue and default chosen

 -- Mathieu Lafon <email address hidden> Thu, 05 Oct 2017 09:32:55 +0200

1716429 pykerberos for trusty does not include CVE-2015-3206 fix
CVE-2015-3206 The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a



About   -   Send Feedback to @ubuntu_updates