-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 3 Apr 2007 15:53:47 -0700 Source: krb5 Binary: krb5-doc libkrb5-dev krb5-rsh-server krb5-user krb5-ftpd libkadm55 libkrb53 krb5-clients krb5-telnetd krb5-kdc krb5-admin-server Architecture: ia64 Version: 1.3.6-4ubuntu0.2 Distribution: breezy-security Urgency: low Maintainer: Ubuntu/ia64 Build Daemon Changed-By: Kees Cook Description: krb5-admin-server - MIT Kerberos master server (kadmind) krb5-clients - Secure replacements for ftp, telnet and rsh using MIT Kerberos krb5-ftpd - Secure FTP server supporting MIT Kerberos krb5-kdc - MIT Kerberos key server (KDC) krb5-rsh-server - Secure replacements for rshd and rlogind using MIT Kerberos krb5-telnetd - Secure telnet server supporting MIT Kerberos krb5-user - Basic programs to authenticate using MIT Kerberos libkadm55 - MIT Kerberos administration runtime libraries libkrb5-dev - Headers and development libraries for MIT Kerberos libkrb53 - MIT Kerberos runtime libraries Changes: krb5 (1.3.6-4ubuntu0.2) breezy-security; urgency=low . * SECURITY UPDATE: arbitrary login via telnet, arbitrary code execution via syslog buffer overflows, and heap corruption via GSS api. * src/appl/telnet/telnetd/{state,sys_term}.c: MIT-SA-2007-1 fix from upstream (CVE-2007-0956). * src/lib/kadm5/logger.c: MIT-SA-2007-2 fix from Debian, based on upstream fixes (CVE-2007-0957). * src/lib/gssapi/krb5/k5unseal.c: MIT-SA-2007-3 fix from upstream (CVE-2007-1216). * References http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-001-telnetd.txt http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-002-syslog.txt http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-003.txt Files: e12504be36543c656b22e07c6a5dbbb5 259286 libs optional libkadm55_1.3.6-4ubuntu0.2_ia64.deb 5369b61d42cbe19e268db1d53ced376f 518536 libs standard libkrb53_1.3.6-4ubuntu0.2_ia64.deb e4f09fc62ec401a8d4d75a850bb85b62 177774 net optional krb5-user_1.3.6-4ubuntu0.2_ia64.deb 6ccd353182fd56b2190bcb329856689e 307212 net optional krb5-clients_1.3.6-4ubuntu0.2_ia64.deb 233d9088f469ee62b81b583999371c63 109640 net optional krb5-rsh-server_1.3.6-4ubuntu0.2_ia64.deb 41e13c712c366d29b1dfb22f94ee0f4f 76082 net extra krb5-ftpd_1.3.6-4ubuntu0.2_ia64.deb 4c64c5704cd48d922a4f085f1076c0e8 88702 net extra krb5-telnetd_1.3.6-4ubuntu0.2_ia64.deb 9719e18380f24e8d8a691c332ee462ef 182410 net optional krb5-kdc_1.3.6-4ubuntu0.2_ia64.deb d89bed0b2c2d8d10daf57093b579ba18 146318 net optional krb5-admin-server_1.3.6-4ubuntu0.2_ia64.deb c4011a00d50f04516705a8dcd337df43 925498 libdevel extra libkrb5-dev_1.3.6-4ubuntu0.2_ia64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFGEuOc0N0xjzyQZEIRArEPAJ42yCEhiebQMIhYgfNZtxPCS5LrwgCeJjad 5eL+ZJEPCIcBGbPIovUahSQ= =m3G+ -----END PGP SIGNATURE-----