ELA-308-1 krb5 security update
Package krb5
ELA-308-1 krb5 security update
Version 1.12.1+dfsg-19+deb8u6
Related CVEs CVE-2020-28196
It was discovered that there was a denial of service vulnerability in the MIT Kerberos network authentication system, krb5. The lack of a limit in the “ASN.1” decoder could lead to infinite recursion and allow an attacker to overrun the stack and cause the process to crash.
For Debian 8 Jessie, these problems have been fixed in version 1.12.1+dfsg-19+deb8u6.
We recommend that you upgrade your krb5 packages.
Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/
A krb5 security update has been released for Debian GNU/Linux 8 Extended LTS to address a denial of service vulnerability in the MIT Kerberos network authentication system.