Bug#773226: CVE-2014-5353: misused policy name crashes KDC

2014-12-15 Thread Benjamin Kaduk
control: severity -1 important Sigh, failed to set severity in the initial report. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#773226: CVE-2014-5353: misused policy name crashes KDC

2014-12-15 Thread Benjamin Kaduk
package: krb5-kdc-ldap version: 1.8.3+dfsg-4squeeze7 tags: security pending Upstream has patched CVE-2014-5353: In MIT krb5, when kadmind is configured to use LDAP for the KDC database, an authenticated remote attacker can cause a NULL dereference by attempting to use a named ticket p