#10738: krb5-1.16.1
-------------------------+-----------------------
Reporter: bdubbs | Owner: bdubbs
Type: enhancement | Status: assigned
Priority: normal | Milestone: 8.3
Component: BOOK | Version: SVN
Severity: normal | Resolution:
Keywords: |
-------------------------+-----------------------
Comment (by bdubbs):
This is a bug fix release.
- Fix flaws in LDAP DN checking, including a null dereference KDC crash
which could be triggered by kadmin clients with administrative privileges
[CVE-2018-5729, CVE-2018-5730].
- Fix a KDC PKINIT memory leak.
- Fix a small KDC memory leak on transited or authdata errors when
processing TGS requests.
- Fix a regression in pkinit_cert_match matching of client certificates
containing Microsoft UPN SANs.
- Fix a null dereference when the KDC sends a large TGS reply.
- Fix "kdestroy -A" with the KCM credential cache type.
- Allow validation of Microsoft PACs containing enterprise names.
- Fix the handling of capaths "." values.
- Fix handling of repeated subsection specifications in profile files
(such as when multiple included files specify relations in the same
subsection).
--
Ticket URL: <http://wiki.linuxfromscratch.org/blfs/ticket/10738#comment:2>
BLFS Trac <http://wiki.linuxfromscratch.org/blfs>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/listinfo/blfs-book
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page