Your message dated Sat, 31 Jul 2021 20:18:17 +0000
with message-id <[email protected]>
and subject line Bug#991365: fixed in krb5 1.17-3+deb10u2
has caused the Debian Bug report #991365,
regarding krb5: CVE-2021-36222
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
991365: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991365
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: krb5
Version: 1.18.3-5
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for krb5.
CVE-2021-36222[0]:
| sending a request containing a PA-ENCRYPTED-CHALLENGE padata element
| without using FAST could result in null dereference in the KDC which
| leads to DoS
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2021-36222
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36222
[1] https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: krb5
Source-Version: 1.17-3+deb10u2
Done: Benjamin Kaduk <[email protected]>
We believe that the bug you reported is fixed in the latest version of
krb5, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Benjamin Kaduk <[email protected]> (supplier of updated krb5 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 22 Jul 2021 18:11:15 -0700
Source: krb5
Architecture: source
Version: 1.17-3+deb10u2
Distribution: buster-security
Urgency: high
Maintainer: Sam Hartman <[email protected]>
Changed-By: Benjamin Kaduk <[email protected]>
Closes: 991365
Changes:
krb5 (1.17-3+deb10u2) buster-security; urgency=high
.
* Import upstream patch for CVE-2021-36222, Closes: #991365
Checksums-Sha1:
d676458263e25761536bdab8b020c281c7587b28 3728 krb5_1.17-3+deb10u2.dsc
3bbc74460767ba7b275b092721a287f49ecf1d0e 102064
krb5_1.17-3+deb10u2.debian.tar.xz
Checksums-Sha256:
a901f59b3c3ddfa56bf34188f644ecdabcf58ea8bd24734ea028a33c91d58f44 3728
krb5_1.17-3+deb10u2.dsc
8a943f0b23f68e74809f8e23b55e1b8af638242b464cf04770aa0324b5ba117c 102064
krb5_1.17-3+deb10u2.debian.tar.xz
Files:
a87f7c9b2b42c3662faf2a5e6d4118bc 3728 net optional krb5_1.17-3+deb10u2.dsc
e756248ac465e282366c1dfa51ed12ff 102064 net optional
krb5_1.17-3+deb10u2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmD6rCRfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EDE4P/3oGaHSq+lErhWaGCB01lntZl7UDHPV3
SWp36Nm5ydNSW0JDRoDFxnca7soCNbdjqaMIhR/6al0PSdakk7zJCjqAq2OmCHc+
o7E+XRru4DuAn5cYKQ7Q+XdymTjZqak1w7s3oTxfT7qZqV/OC72gTFco6UV3A2MN
ON2ZUteMRcvQZwBbmfY3njSZMaKmWc4loIhMAP9EU+maEzGSRdCsaxWuhz7lZF2J
pkNfTxk/GeN0WPMt1j1Mik2lrPx4n/PNMWeI0+EPyW9jQrn4/15NTT3MVFxZHfP9
dsd5WDUn/N7uikiCElnSFe6OQlERxAHCHyKuA4sI1vLBH7XOJ2xH/deOZijo2FuX
3YjQEB/I+Nu/mU1Arfi4KO1EmirBh0EqqaZyioS/J1f5VnidDgytvQp3PrZTdxDF
IdMxsxkIsm8j3FEBR/bu3ncJl5Mbs/zUFwXVrRYXlrlpQ6n0DhizX334esDPoBpq
vifXM2RpPdwf5w0M+4IA96igh5IwCerFFn2sDwJEYs8FEmPopfhi2lXgG/fz0eWD
DK1WgFlFz2sIETUk4g3VeEO6Vgb+x+uQDDhsmDuOCdkyndpZkNreKwxqMAOGgxqX
9j3IBvl5M48IXLfg4sutUZFvjpulnnyQ0Y3DWd7Id1Dkh0TjNv4Vmo4TZ/13eAyq
SEOwWBB+onXi
=eQ0G
-----END PGP SIGNATURE-----
--- End Message ---