Advisories ยป MGASA-2021-0022

Updated krb5 packages fix a security vulnerability

Publication date: 14 Jan 2021
Modification date: 14 Jan 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-28196

Description

MIT Kerberos 5 (aka krb5) before 1.17.2 allows unbounded recursion via an
ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support
for BER indefinite lengths lacks a recursion limit (CVE-2020-28196).
                

References

SRPMS

7/core