--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-0503
2010-01-14 00:54:30
--------------------------------------------------------------------------------
Name : krb5
Product : Fedora 12
Version : 1.7
Release : 18.fc12
URL :
http://web.mit.edu/kerberos/www/
Summary : The Kerberos network authentication system
Description :
Kerberos V5 is a trusted-third-party network authentication system,
which can improve your network's security by eliminating the insecure
practice of cleartext passwords.
--------------------------------------------------------------------------------
Update Information:
This update incorporates fixes from upstream which correct integer underflow
problems in the AES and RC4 decryption routines (CVE-2009-4212). It also
corrects a failure in 'kdb5_util load' which could occur when the database files
being created did not previously exist.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jan 12 2010 Nalin Dahyabhai <nalin@redhat.com> - 1.7-18
- add upstream patch for integer underflow during AES and RC4 decryption
(CVE-2009-4212), via Tom Yu (#545015)
* Wed Jan 6 2010 Nalin Dahyabhai <nalin@redhat.com> - 1.7-17
- put the conditional back for the -devel subpackage
- back down to the earlier version of the patch for #551764; the backported
alternate version was incomplete
* Tue Jan 5 2010 Nalin Dahyabhai <nalin@redhat.com> - 1.7-16
- use %global instead of %define
- pull up proposed patch for creating previously-not-there lock files for
kdb databases when 'kdb5_util' is called to 'load' (#551764)
* Mon Jan 4 2010 Dennis Gregorovic <dgregor@redhat.com>
- fix conditional for future RHEL
* Mon Jan 4 2010 Nalin Dahyabhai <nalin@redhat.com> - 1.7-15
- add upstream patch for KDC crash during referral processing (CVE-2009-3295),
via Tom Yu (#545002)
* Mon Dec 21 2009 Nalin Dahyabhai <nalin@redhat.com> - 1.7-14
- refresh patch for #542868 from trunk
* Thu Dec 10 2009 Nalin Dahyabhai <nalin@redhat.com>
- move man pages that live in the -libs subpackage into the regular
%{_mandir} tree where they'll still be found if that package is the
only one installed (#529319)
* Wed Dec 9 2009 Nalin Dahyabhai <nalin@redhat.com> - 1.7-13
- and put it back in
* Tue Dec 8 2009 Nalin Dahyabhai <nalin@redhat.com>
- back that last change out
* Tue Dec 8 2009 Nalin Dahyabhai <nalin@redhat.com> - 1.7-12
- try to make gss_krb5_copy_ccache() work correctly for spnego (#542868)
* Fri Dec 4 2009 Nalin Dahyabhai <nalin@redhat.com>
- make krb5-config suppress CFLAGS output when called with --libs (#544391)
* Thu Dec 3 2009 Nalin Dahyabhai <nalin@redhat.com> - 1.7-11
- ksu: move account management checks to before we drop privileges, like
su does (#540769)
- selinux: set the user part of file creation contexts to match the current
context instead of what we looked up
- configure with --enable-dns-for-realm instead of --enable-dns, which isn't
recognized any more
* Fri Nov 20 2009 Nalin Dahyabhai <nalin@redhat.com> - 1.7-10
- move /etc/pam.d/ksu from krb5-workstation-servers to krb5-workstation,
where it's actually needed (#538703)
* Fri Oct 23 2009 Nalin Dahyabhai <nalin@redhat.com> - 1.7-9
- add some conditional logic to simplify building on older Fedora releases
* Tue Oct 13 2009 Nalin Dahyabhai <nalin@redhat.com>
- don't forget the README
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #545015 - CVE-2009-4212 krb: KDC integer overflows in AES and RC4 decryption routines (MITKRB5-SA-2009-004)
https://bugzilla.redhat.com/show_bug.cgi?id=545015
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update krb5' at the command line.
For more information, refer to "Managing Software with yum",
available at
http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce