Debian 9914 Published by

A krb5 security update has been released for Debian GNU/Linux 8 Extended LTS to address a denial of service vulnerability in the MIT Kerberos network authentication system.



ELA-308-1 krb5 security update

Package krb5
Version 1.12.1+dfsg-19+deb8u6
Related CVEs CVE-2020-28196

It was discovered that there was a denial of service vulnerability in the MIT Kerberos network authentication system, krb5. The lack of a limit in the “ASN.1” decoder could lead to infinite recursion and allow an attacker to overrun the stack and cause the process to crash.

For Debian 8 Jessie, these problems have been fixed in version 1.12.1+dfsg-19+deb8u6.

We recommend that you upgrade your krb5 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-308-1 krb5 security update