[El-errata] ELSA-2009-0409 Important: Enterprise Linux 4 krb5 security update

Errata Announcements for Enterprise Linux el-errata at oss.oracle.com
Tue Apr 7 18:27:20 PDT 2009


Enterprise Linux Security Advisory ELSA-2009-0409

https://rhn.redhat.com/errata/RHSA-2009-0409.html

The following updated rpms for Enterprise Linux 4 have been uploaded to 
the Unbreakable Linux Network:

i386:
krb5-devel-1.3.4-60.el4_7.2.i386.rpm
krb5-libs-1.3.4-60.el4_7.2.i386.rpm
krb5-server-1.3.4-60.el4_7.2.i386.rpm
krb5-workstation-1.3.4-60.el4_7.2.i386.rpm

x86_64:
krb5-devel-1.3.4-60.el4_7.2.x86_64.rpm
krb5-libs-1.3.4-60.el4_7.2.i386.rpm
krb5-libs-1.3.4-60.el4_7.2.x86_64.rpm
krb5-server-1.3.4-60.el4_7.2.x86_64.rpm
krb5-workstation-1.3.4-60.el4_7.2.x86_64.rpm

ia64:
krb5-devel-1.3.4-60.el4_7.2.ia64.rpm
krb5-libs-1.3.4-60.el4_7.2.i386.rpm
krb5-libs-1.3.4-60.el4_7.2.ia64.rpm
krb5-server-1.3.4-60.el4_7.2.ia64.rpm
krb5-workstation-1.3.4-60.el4_7.2.ia64.rpm

SRPMS:
http://oss.oracle.com/el4/SRPMS-updates/krb5-1.3.4-60.el4_7.2.src.rpm

Description of changes:

[1.3.4-60.el4_7.2]
- whoops, actually add the patches

[1.3.4-60.el4_7.1]
- add fix for attempt to free uninitialized pointer in the ASN.1 decoder
  (#491835, CVE-2009-0846)
- add fix for bug in length validation in the ASN.1 decoder (CVE-2009-0847)





More information about the El-errata mailing list