Updated krb5 packages fix security vulnerability
Publication date: 10 Jan 2019Modification date: 10 Jan 2019
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-20217
Description
An authenticated user who can obtain a TGT using an older encryption type (DES, DES3, or RC4) can cause an assertion failure in the KDC by sending an S4U2Self request (CVE-2018-20217).
References
SRPMS
6/core
- krb5-1.15.1-2.4.mga6