Bug#773228: CVE-2014-5354: kadmin crashes on keyless principals

2014-12-15 Thread Benjamin Kaduk
[removing submit@] On Mon, 15 Dec 2014, Sam Hartman wrote: > control: severity -1 important > > It might be worth getting these two into jessie if the release team is > willing. I think pre-approved fixes are valid until KJanuary 5 and so > we should figure out how to get pre-approval if you agr

Bug#773228: CVE-2014-5354: kadmin crashes on keyless principals

2014-12-15 Thread Sam Hartman
control: severity -1 important It might be worth getting these two into jessie if the release team is willing. I think pre-approved fixes are valid until KJanuary 5 and so we should figure out how to get pre-approval if you agree. --sam -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lis

Bug#773228: CVE-2014-5354: kadmin crashes on keyless principals

2014-12-15 Thread Benjamin Kaduk
package: krb5-kdc-ldap version: 1.12.1+dfsg-15 tags: security pending Upstream has patched CVE-2014-5354: In MIT krb5, when kadmind is configured to use LDAP for the KDC database, an authenticated remote attacker can cause a NULL dereference by inserting into the database a principal