Multiple CVEs in krb5: CVE-2014-5352 CVE-2014-9421 CVE-2014-9422 CVE-2014-9423 1) CVE-2014-5352 krb5: gss_process_context_token() incorrectly frees context (MITKRB5-SA-2015-001) Upstream commit: https://github.com/krb5/krb5/commit/82dc33da50338ac84c7b4102dc6513d897d0506a External references: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-5352 http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt ----------------------------------------------------------------- 2) CVE-2014-9421 krb5: kadmind doubly frees partial deserialization results (MITKRB5-SA-2015-001) Upstream commit: https://github.com/krb5/krb5/commit/a197e92349a4aa2141b5dff12e9dd44c2a2166e3 External References: http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-9421 ----------------------------------------------------------------- 3) CVE-2014-9422 krb5: kadmind incorrectly validates server principal name (MITKRB5-SA-2015-001) Upstream commit: https://github.com/krb5/krb5/commit/6609658db0799053fbef0d7d0aa2f1fd68ef32d8 External References: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-9422 http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt ----------------------------------------------------------------- 4) CVE-2014-9423 krb5: libgssrpc server applications leak uninitialized bytes (MITKRB5-SA-2015-001) Upstream commit: https://github.com/krb5/krb5/commit/5bb8a6b9c9eb8dd22bc9526751610aaa255ead9c External References: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-9423 http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
Sorry to be a pain, but krb5 is in meta-oe which is not directly maintained by the Yocto Project, and as such we wouldn't track issues with it in this bugzilla.