Revisions of krb5
Ana Guerrero (anag+factory)
accepted
request 1134351
from
Dirk Mueller (dirkmueller)
(revision 169)
- update to 1.21.2 (bsc#1218211, CVE-2023-39975): * Fix double-free in KDC TGS processing [CVE-2023-39975]. - update to 1.21.1 (CVE-2023-36054): with Windows KDCs.
Ana Guerrero (anag+factory)
accepted
request 1098841
from
Dirk Mueller (dirkmueller)
(revision 167)
- update to 1.121.1 (CVE-2023-36054): * Fix potential uninitialized pointer free in kadm5 XDR parsing [CVE-2023-36054]. * Added a credential cache type providing compatibility with the macOS 11 native credential cache. * libkadm5 will use the provided krb5_context object to read configuration values, instead of creating its own. * Added an interface to retrieve the ticket session key from a GSS context. * The KDC will no longer issue tickets with RC4 or triple-DES session keys unless explicitly configured with the new allow_rc4 or allow_des3 variables respectively. * The KDC will assume that all services can handle aes256-sha1 session keys unless the service principal has a session_enctypes string attribute. * Support for PAC full KDC checksums has been added to mitigate an S4U2Proxy privilege escalation attack. * The PKINIT client will advertise a more modern set of supported CMS algorithms. * Removed unused code in libkrb5, libkrb5support, and the PKINIT module. * Modernized the KDC code for processing TGS requests, the code for encrypting and decrypting key data, the PAC handling code, and the GSS library packet parsing and composition code. * Improved the test framework's detection of memory errors in daemon processes when used with asan.
Dominique Leuenberger (dimstar_suse)
accepted
request 1084720
from
Dirk Mueller (dirkmueller)
(revision 166)
Dominique Leuenberger (dimstar_suse)
accepted
request 1074019
from
Samuel Cabrero (scabrero)
(revision 165)
Dominique Leuenberger (dimstar_suse)
accepted
request 1069660
from
Dirk Mueller (dirkmueller)
(revision 164)
Dominique Leuenberger (dimstar_suse)
accepted
request 1069137
from
Factory Maintainer (factory-maintainer)
(revision 163)
Automatic submission by obs-autosubmit
Dominique Leuenberger (dimstar_suse)
accepted
request 1042851
from
Marcus Meissner (msmeissn)
(revision 162)
Dominique Leuenberger (dimstar_suse)
accepted
request 1036481
from
Dirk Mueller (dirkmueller)
(revision 161)
Dominique Leuenberger (dimstar_suse)
accepted
request 981266
from
Factory Maintainer (factory-maintainer)
(revision 160)
Automatic submission by obs-autosubmit
Dominique Leuenberger (dimstar_suse)
accepted
request 970776
from
Marcus Meissner (msmeissn)
(revision 159)
Dominique Leuenberger (dimstar_suse)
accepted
request 949613
from
Samuel Cabrero (scabrero)
(revision 158)
Dominique Leuenberger (dimstar_suse)
accepted
request 922420
from
Samuel Cabrero (scabrero)
(revision 157)
Dominique Leuenberger (dimstar_suse)
accepted
request 917690
from
Samuel Cabrero (scabrero)
(revision 156)
Dominique Leuenberger (dimstar_suse)
accepted
request 894925
from
Dirk Mueller (dirkmueller)
(revision 154)
Dominique Leuenberger (dimstar_suse)
accepted
request 888170
from
Marcus Meissner (msmeissn)
(revision 153)
Dominique Leuenberger (dimstar_suse)
accepted
request 884639
from
Peter Varkoly (varkoly)
(revision 152)
Displaying revisions 1 - 20 of 170