Updated krb5 packages fix a security vulnerability
Publication date: 14 Jan 2021Modification date: 14 Jan 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-28196
Description
MIT Kerberos 5 (aka krb5) before 1.17.2 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit (CVE-2020-28196).
References
SRPMS
7/core
- krb5-1.17-2.1.mga7