krb5-1.10.3-10.el6_4.3.src
[11.5 MiB] |
Changelog
by Nalin Dahyabhai (2013-05-31):
- pull up fix for UDP ping-pong flaw in kpasswd service (CVE-2002-2443,
|
krb5-1.10.3-10.el6_4.2.src
[11.5 MiB] |
Changelog
by Nalin Dahyabhai (2013-04-09):
- incorporate upstream patch to fix a NULL pointer dereference while processing
certain TGS requests (CVE-2013-1416, #950342)
|
krb5-1.10.3-10.el6_4.1.src
[11.5 MiB] |
Changelog
by Nalin Dahyabhai (2013-03-05):
- incorporate upstream patch to fix a NULL pointer dereference when the client
supplies an otherwise-normal-looking PKINIT request (CVE-2013-1415, #917909)
- add patch to avoid dereferencing a NULL pointer in the KDC when handling a
draft9 PKINIT request (#917909, CVE-2012-1016)
|
krb5-1.10.3-10.el6.src
[11.5 MiB] |
Changelog
by Nalin Dahyabhai (2012-12-18):
- make -server conflict with older versions of SELinux policy that didn't
allow us to use eventfds, which libverto's backend may depend on in order
to properly shut down a multi-worker KDC (#871524)
|
krb5-1.9-33.el6_3.3.src
[12.2 MiB] |
Changelog
by Nalin Dahyabhai (2012-09-06):
- cut down the number of times we load SELinux labeling configuration from
a minimum of two times to actually one (#852455)
|
krb5-1.9-33.el6_3.2.src
[12.2 MiB] |
Changelog
by Nalin Dahyabhai (2012-07-19):
- pull up the patch to correct a possible NULL pointer dereference in
kadmind (CVE-2012-1013, #827517)
|
krb5-1.9-33.el6.src
[12.2 MiB] |
Changelog
by Nalin Dahyabhai (2012-04-18):
- selinux: reliably reset the file creation context after setting it when we
flush replay caches, in cases where there was none explicitly set beforehand
(#813883)
|
krb5-1.9-22.el6_2.1.src
[12.2 MiB] |
Changelog
by Nalin Dahyabhai (2011-11-17):
- add candidate patch to fix a NULL pointer dereference while processing TGS
requests (MITKRB5-SA-2011-007, #754046)
|
krb5-1.9-22.el6.src
[12.2 MiB] |
Changelog
by Nalin Dahyabhai (2011-10-18):
- handle a harder-to-trigger assertion failure that starts cropping up when we
exit the transmit loop on time (#746341)
- apply upstream patch to fix a null pointer derference with the LDAP kdb
backend (CVE-2011-1527), an assertion failure with multiple kdb backends
(CVE-2011-1528), and a null pointer dereference with multiple kdb backends
(CVE-2011-1529) (MITKRB5-SA-2011-006, #740085)
|
krb5-1.9-9.el6_1.2.slf.src
[12.2 MiB] |
Changelog
by Nalin Dahyabhai (2011-09-20):
- apply upstream patch to fix a null pointer derference with the LDAP kdb
backend (CVE-2011-1527), an assertion failure with multiple kdb backends
(CVE-2011-1528), and a null pointer dereference with multiple kdb backends
(CVE-2011-1529) (#740084)
|
krb5-1.9-9.el6_1.2.src
[12.2 MiB] |
Changelog
by Nalin Dahyabhai (2011-09-20):
- apply upstream patch to fix a null pointer derference with the LDAP kdb
backend (CVE-2011-1527), an assertion failure with multiple kdb backends
(CVE-2011-1528), and a null pointer dereference with multiple kdb backends
(CVE-2011-1529) (#740084)
|
krb5-1.9-9.el6_1.1.src
[12.2 MiB] |
Changelog
by Nalin Dahyabhai (2011-06-21):
- apply upstream patch by way of Burt Holzman to fall back to a non-referral
method in cases where we might be derailed by a KDC that rejects the
canonicalize option (for example, those from the RHEL 2.1 or 3 era) (#714866)
|
krb5-1.9-9.el6.src
[12.2 MiB] |
Changelog
by Nalin Dahyabhai (2011-04-13):
- kadmind: add upstream patch to fix free() on an invalid pointer (#696342,
MITKRB5-SA-2011-004, CVE-2011-0285)
|
krb5-1.8.2-3.el6_0.7.src
[12.0 MiB] |
Changelog
by Nalin Dahyabhai (2011-04-13):
- kadmind: add upstream patch to fix free() on an invalid pointer (#696341,
MITKRB5-SA-2011-004, CVE-2011-0285)
|
krb5-1.8.2-3.el6_0.6.src
[12.0 MiB] |
Changelog
by Nalin Dahyabhai (2011-03-14):
- add revised upstream patch to fix double-free in KDC while returning
typed-data with errors (CVE-2011-0284, #681564)
|
krb5-1.8.2-3.el6_0.4.src
[12.0 MiB] |
Changelog
by Nalin Dahyabhai (2011-01-20):
- add upstream patches to fix standalone kpropd exiting if the per-client
child process exits with an error, and hang or crash in the KDC when using
the LDAP kdb backend (CVE-2010-4022, CVE-2011-0281, CVE-2011-0282, #671101)
|
krb5-1.8.2-3.el6_0.3.src
[11.9 MiB] |
Changelog
by Nalin Dahyabhai (2010-11-05):
- pull up crypto changes made between 1.8.2 and 1.8.3 to fix upstream #6751,
assumed to already be there for the next fix
- incorporate candidate patch to fix various issues from MITKRB5-SA-2010-007
(CVE-2010-1323, CVE-2010-1324, CVE-2010-4020, #651962)
|
krb5-1.8.2-3.el6_0.1.src
[11.9 MiB] |
Changelog
by Nalin Dahyabhai (2010-09-23):
- incorporate candidate patch to fix uninitialized pointer crash in the KDC
(CVE-2010-1322, #636336)
|
krb5-1.8.2-3.el6.src
[11.9 MiB] |
Changelog
by Nalin Dahyabhai (2010-09-03):
- build with -fstack-protector-all instead of the default -fstack-protector,
so that we add checking to more functions (i.e., all of them) (#629950)
- also link binaries with -Wl,-z,relro,-z,now (part of #629950)
|