Your message dated Wed, 21 Jul 2021 20:48:40 +0000
with message-id <[email protected]>
and subject line Bug#991365: fixed in krb5 1.18.3-6
has caused the Debian Bug report #991365,
regarding krb5: CVE-2021-36222
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
991365: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991365
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: krb5
Version: 1.18.3-5
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for krb5.
CVE-2021-36222[0]:
| sending a request containing a PA-ENCRYPTED-CHALLENGE padata element
| without using FAST could result in null dereference in the KDC which
| leads to DoS
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2021-36222
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36222
[1] https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: krb5
Source-Version: 1.18.3-6
Done: Benjamin Kaduk <[email protected]>
We believe that the bug you reported is fixed in the latest version of
krb5, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Benjamin Kaduk <[email protected]> (supplier of updated krb5 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 21 Jul 2021 11:07:07 -0700
Source: krb5
Architecture: source
Version: 1.18.3-6
Distribution: unstable
Urgency: high
Maintainer: Sam Hartman <[email protected]>
Changed-By: Benjamin Kaduk <[email protected]>
Closes: 991365
Changes:
krb5 (1.18.3-6) unstable; urgency=high
.
* Pull in upstream patch to fix CVE-2021-36222 (KDC NULL dereference),
Closes: #991365
Checksums-Sha1:
2415bb11cfdf8cca14f8a96e8589a8308c87bdeb 3636 krb5_1.18.3-6.dsc
0c66f51a59ac6b4e2b9d5f421c5d5c6c66bb72ff 105116 krb5_1.18.3-6.debian.tar.xz
c91e51a6c92935affe71c24ddd528c4da06bf66f 19700 krb5_1.18.3-6_amd64.buildinfo
Checksums-Sha256:
f56d9348388f1f8b55006bd657292939332025e94251feb18463218553d0b44f 3636
krb5_1.18.3-6.dsc
f5f85252688ccab0c5c333728911eaf69f9a9759033cba7687435d41f9d5e595 105116
krb5_1.18.3-6.debian.tar.xz
3a00f9798b4ecff884d536d327293386caddb43886ccbbb78cd0abd1d39caddb 19700
krb5_1.18.3-6_amd64.buildinfo
Files:
e5d7dd4b7b6f7b754abb2440f5956847 3636 net optional krb5_1.18.3-6.dsc
e00149582ff1f5d905f65cdb7438345f 105116 net optional
krb5_1.18.3-6.debian.tar.xz
41ee1e822ea5f2726fdce440839d5151 19700 net optional
krb5_1.18.3-6_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQHGBAEBCgAsFiEE2WGV4E2ARf9BYP0XKNmm82TrdRIFAmD4hRAOHGthZHVrQG1p
dC5lZHUACgkQKNmm82TrdRJgfAwg12nraRi7CaqUC/MN4iVII9ulAV4sdZPWXkSg
bWHtX/uupg7Ge96HQM6Gj/vyPSp6N2iVXdsX42OsoMDFC0nYYUs2yBvauHZ59xr/
X86RJhjZdCSEOJntXAFkiA76Ktr3FaIpH7lhR3cu4444+NwTbDma0w9HIOd4GybE
BoW8SEoIm/wezNOVjHt5xdEO8VS3iNzdjTZMZIe/y1x9asXfWoOchiaBeIo6cjlm
jL05OC5mkmrbpxsVldXtZ8bvKZ6ALe6YQ8Tk91i2FXK8cuzQmyAQ5MhqOpn0n3hH
/Mi2ncrtjoXHNGsg6CbGPaWQdLk1KpitEduXrjUqYqTr3USDAZJeuXcbA4/fEwjF
bJVHCtLnN7F3ulF7UuKW/f/8Iape40WTvnCEJfOq/Feeg6RAwej7657faHLfcHbV
9Tk3Xgn4URuCVKS4QGnqUdP5V0RDAjZeATXFR7yvUjThgWl0zWb0tW6vIJq//Lqt
qiAUai+4PneWUUwFzqjlClV1tFdtIJpfCg==
=twWX
-----END PGP SIGNATURE-----
--- End Message ---