{"id":"SUSE-SU-2015:0257-1","summary":"Security update for krb5","details":"\nkrb5 has been updated to fix four security issues:\n\n    * CVE-2014-5352: gss_process_context_token() incorrectly frees context\n      (bsc#912002)\n    * CVE-2014-9421: kadmind doubly frees partial deserialization results\n      (bsc#912002)\n    * CVE-2014-9422: kadmind incorrectly validates server principal name\n      (bsc#912002)\n    * CVE-2014-9423: libgssrpc server applications leak uninitialized bytes\n      (bsc#912002)\n\nAdditionally, these non-security issues have been fixed:\n\n    * Winbind process hangs indefinitely without DC. (bsc#872912)\n    * Hanging winbind processes. (bsc#906557)\n\nSecurity Issues:\n\n    * CVE-2014-5352\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5352\u003e\n    * CVE-2014-9421\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9421\u003e\n    * CVE-2014-9422\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9422\u003e\n    * CVE-2014-9423\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9423\u003e\n\n","modified":"2026-03-11T05:59:40.884380Z","published":"2015-02-06T09:35:09Z","related":["CVE-2014-5352","CVE-2014-9421","CVE-2014-9422","CVE-2014-9423"],"upstream":["CVE-2014-5352","CVE-2014-9421","CVE-2014-9422","CVE-2014-9423"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150257-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/872912"},{"type":"REPORT","url":"https://bugzilla.suse.com/906557"},{"type":"REPORT","url":"https://bugzilla.suse.com/912002"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-5352"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-9421"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-9422"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-9423"}],"schema_version":"1.7.5"}