Bug#755520: CVE-2014-4343 in krb5: double-free in SPNEGO initiators

2014-07-21 Thread Benjamin Kaduk
Package: libgssapi-krb5-2 Version: 1.10.1+dfsg-5+deb7u1 Upstream has committed a fix for CVE-2014-4343 to their git repo; we should take it as well, and probably push it back into the -security repos for stable. It's a double-free in clients, but not the default configuration. I should be

Bug#755520: CVE-2014-4343 in krb5: double-free in SPNEGO initiators

2014-07-21 Thread Sam Hartman
I'm not at ietf this week. If you corner me on Jabber I'm happy to coordinate on an unstable upload. If you get a go ahead from security for any of this I'm happy to help with a stable upload -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe.