Errata overview
Errata ID 113
Date 2015-03-12
Source package krb5
Fixed in version 1.10.1+dfsg-5.57.201503101742
Description
Multiple vulnerabilities have been found in MIT Kerberos:
* gss_process_context_token() incorrectly frees a context (CVE-2014-5352)
* kadmind doubly frees partial deserialization results (CVE-2014-9421)
* kadmind incorrectly validates server principal name (CVE-2014-9422)
* libgssrpc server applications leak uninitialised bytes (CVE-2014-9423)
Additional notes
CVE ID CVE-2014-5352
CVE-2014-9421
CVE-2014-9422
CVE-2014-9423
UCS Bug number #37680