Fedora 21 Security Update: krb5-1.12.2-17.fc21

Resolved Bugs
1216134 – CVE-2015-2694 krb5: issues in OTP and PKINIT kdcpreauth modules leading to requires_preauth bypass [fedora-21]
1174544 – CVE-2014-5353 krb5: NULL pointer dereference when using a ticket policy name as a password policy name [fedora-all]
1216133 – CVE-2015-2694 krb5: issues in OTP and PKINIT kdcpreauth modules leading to requires_preauth bypass
1174543 – CVE-2014-5353 krb5: NULL pointer dereference when using a ticket policy name as a password policy name<br
Security fix for CVE-2015-2694
Security fix for CVE-2014-5353
(this was fixed in an older build but the announcement was lost)

Leave a Reply