Advisories ยป MGASA-2019-0028

Updated krb5 packages fix security vulnerability

Publication date: 10 Jan 2019
Modification date: 10 Jan 2019
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-20217

Description

An authenticated user who can obtain a TGT using an older encryption
type (DES, DES3, or RC4) can cause an assertion failure in the KDC by
sending an S4U2Self request (CVE-2018-20217).
                

References

SRPMS

6/core