MGASA-2015-0446

Source
https://advisories.mageia.org/MGASA-2015-0446.html
Import Source
https://advisories.mageia.org/MGASA-2015-0446.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2015-0446
Related
Published
2015-11-16T21:36:58Z
Modified
2015-11-16T21:31:36Z
Summary
Updated krb5 packages fix CVE-2015-2698
Details

Updated krb5 packages fix security vulnerabilities:

In any MIT krb5 release with the patches for CVE-2015-2696 applied, an application which calls gssexportsec_context() may experience memory corruption if the context was established using the IAKERB mechanism. Historically, some vulnerabilities of this nature can be translated into remote code execution, though the necessary exploits must be tailored to the individual application and are usually quite complicated (CVE-2015-2698).

References
Credits

Affected packages

Mageia:5 / krb5

Package

Name
krb5
Purl
pkg:rpm/mageia/krb5?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.2-8.2.mga5

Ecosystem specific

{
    "section": "core"
}