Bug 7303

Summary: krb5: multiple CVEs, CVE-2014-5352 CVE-2014-9421 CVE-2014-9422 CVE-2014-9423
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Sona Sarmadi <sona.sarmadi>
Component: connectivityAssignee: Cristian Iorga <cristian.iorga>
Status: RESOLVED INVALID QA Contact:
Severity: normal    
Priority: Undecided CC: bluelightning, meta.mr.watcher, meta.watcher
Version: unspecified   
Target Milestone: ---   
Hardware: All   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Sona Sarmadi 2015-02-10 13:30:33 UTC
Multiple CVEs in krb5: CVE-2014-5352 CVE-2014-9421 CVE-2014-9422 CVE-2014-9423

1) CVE-2014-5352 krb5: gss_process_context_token() incorrectly frees context (MITKRB5-SA-2015-001) 

Upstream commit:
https://github.com/krb5/krb5/commit/82dc33da50338ac84c7b4102dc6513d897d0506a

External references:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-5352
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
-----------------------------------------------------------------
2) CVE-2014-9421 krb5: kadmind doubly frees partial deserialization results (MITKRB5-SA-2015-001)

Upstream commit:
https://github.com/krb5/krb5/commit/a197e92349a4aa2141b5dff12e9dd44c2a2166e3

External References:
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-9421
-----------------------------------------------------------------
3) CVE-2014-9422 krb5: kadmind incorrectly validates server principal name (MITKRB5-SA-2015-001)

Upstream commit:
https://github.com/krb5/krb5/commit/6609658db0799053fbef0d7d0aa2f1fd68ef32d8

External References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-9422
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
-----------------------------------------------------------------
4)  CVE-2014-9423 krb5: libgssrpc server applications leak uninitialized bytes (MITKRB5-SA-2015-001)

Upstream commit:
https://github.com/krb5/krb5/commit/5bb8a6b9c9eb8dd22bc9526751610aaa255ead9c

External References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-9423
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
Comment 1 Paul Eggleton 2015-02-10 16:44:33 UTC
Sorry to be a pain, but krb5 is in meta-oe which is not directly maintained by the Yocto Project, and as such we wouldn't track issues with it in this bugzilla.