Bug 7303 - krb5: multiple CVEs, CVE-2014-5352 CVE-2014-9421 CVE-2014-9422 CVE-2014-9423
Summary: krb5: multiple CVEs, CVE-2014-5352 CVE-2014-9421 CVE-2014-9422 CVE-2014-9423
Status: RESOLVED INVALID
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: connectivity (show other bugs)
Version: unspecified
Hardware: All Multiple
: Undecided normal
Target Milestone: ---
Assignee: Cristian Iorga
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2015-02-10 13:30 UTC by Sona Sarmadi
Modified: 2015-02-10 16:44 UTC (History)
3 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sona Sarmadi 2015-02-10 13:30:33 UTC
Multiple CVEs in krb5: CVE-2014-5352 CVE-2014-9421 CVE-2014-9422 CVE-2014-9423

1) CVE-2014-5352 krb5: gss_process_context_token() incorrectly frees context (MITKRB5-SA-2015-001) 

Upstream commit:
https://github.com/krb5/krb5/commit/82dc33da50338ac84c7b4102dc6513d897d0506a

External references:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-5352
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
-----------------------------------------------------------------
2) CVE-2014-9421 krb5: kadmind doubly frees partial deserialization results (MITKRB5-SA-2015-001)

Upstream commit:
https://github.com/krb5/krb5/commit/a197e92349a4aa2141b5dff12e9dd44c2a2166e3

External References:
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-9421
-----------------------------------------------------------------
3) CVE-2014-9422 krb5: kadmind incorrectly validates server principal name (MITKRB5-SA-2015-001)

Upstream commit:
https://github.com/krb5/krb5/commit/6609658db0799053fbef0d7d0aa2f1fd68ef32d8

External References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-9422
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
-----------------------------------------------------------------
4)  CVE-2014-9423 krb5: libgssrpc server applications leak uninitialized bytes (MITKRB5-SA-2015-001)

Upstream commit:
https://github.com/krb5/krb5/commit/5bb8a6b9c9eb8dd22bc9526751610aaa255ead9c

External References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-9423
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
Comment 1 Paul Eggleton 2015-02-10 16:44:33 UTC
Sorry to be a pain, but krb5 is in meta-oe which is not directly maintained by the Yocto Project, and as such we wouldn't track issues with it in this bugzilla.