RT RT/krbdev.mit.edu: Ticket #5919 MITKRB5-SA-2008-001 kdc krb4 double-free [CVE-2008-0062], uninit data [CVE-2008-0063] vulns Signed in as guest.
[Logout]

[Home] [Search] [Configuration]

[<< First] [< Prev] [Next >] [Last >>]

[Display] [History] [Basics] [Dates] [People] [Links] [Jumbo]

 
 

 The Basics  
Id
5919
Status
resolved
Worked
0 min
Priority
0/0
Queue
krb5
 

 Keyword Selections  
Component
  • krb5-kdc
Version_reported
  • 1.6.3
Version_Fixed
  • 1.6.4
Target_Version
  • 1.6.4
Tags
  • pullup
 

 Relationships  
Depends on:
Depended on by:
Parents:
Children:

Refers to:
Referred to by:
  • 5922: (tlyu) (1.5.x) MITKRB5-SA-2008-001 kdc krb4 double-free [CVE-2008-0062], uninit data [CVE-2008-0063] vulns [resolved]
 
 Dates  
Created: Tue Mar 18 15:17:31 2008
Starts: Not set
Started: Tue Mar 18 16:07:19 2008
Last Contact: Wed Mar 19 19:04:08 2008
Due: Not set
Updated: Thu Mar 20 19:41:04 2008 by tlyu
 

 People  
Owner
 raeburn
Requestors
 raeburn@mit.edu
Cc
 
AdminCc
 
 

 More about Ken Raeburn  
Comments about this user:
No comment entered about this user
This user's 25 highest priority tickets:
 

History   Display mode: [Brief headers] [Full headers]
      Tue Mar 18 15:17:32 2008  raeburn - Ticket created    
     
Subject: MITKRB5-SA-2008-001

The patch included in MITKRB5-SA-2008-001 needs to be applied to the 1.6 branch.

The patch that will go onto the trunk will not be applicable to the branch, because
the affected
code has diverged.


Download (untitled) 198b
      Tue Mar 18 16:07:18 2008  raeburn - Given to raeburn    
      Tue Mar 18 16:07:19 2008  raeburn - Status changed from new to resolved    
      Tue Mar 18 16:07:19 2008  raeburn - Correspondence added    
     
From: raeburn@mit.edu
Subject: SVN Commit


Fix MITKRB5-SA-2008-001 on trunk.  Patch differs from the released one
for 1.6 because of code divergence.


Commit By: raeburn



Revision: 20280
Changed Files:
_U  trunk/
U   trunk/src/kdc/dispatch.c
U   trunk/src/kdc/kerberos_v4.c
U   trunk/src/kdc/network.c


Download (untitled) 263b
      Wed Mar 19 19:04:05 2008  tlyu - Version_Fixed 1.6.4 added    
      Wed Mar 19 19:04:05 2008  tlyu - Correspondence added    
     
From: tlyu@mit.edu
Subject: SVN Commit


Apply patch for MITKRB5-SA-2008-001.


Commit By: tlyu



Revision: 20283
Changed Files:
_U  branches/krb5-1-6/
U   branches/krb5-1-6/src/kdc/dispatch.c
U   branches/krb5-1-6/src/kdc/kerberos_v4.c
U   branches/krb5-1-6/src/kdc/network.c


Download (untitled) 238b
      Thu Mar 20 19:41:04 2008  tlyu - Subject changed from MITKRB5-SA-2008-001 to MITKRB5-SA-2008-001 kdc krb4 double-free [CVE-2008-0062], uninit data [CVE-2008-0063] vulns