it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5344-1] heimdal security update
- Date: Wed, 08 Feb 2023 12:46:12 +0000
- Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/E1pPjq0-00CbfC-HU AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=QANAP4Su4I0XKEDpgckAjrUUCUXSI5WFcu5UhAeXzR8=; b=rN vVruf9PKARqI+OXn6AFPYIIbHVQmBF+4KCMdnqHHKw5kxe0vBwArtrhtltNbfPTlB36UsXp/WXG6S +rCyoi5Ucig7O/GRmBu5zgePIPBFfMtrHZBtmO0tipZ+I/eg4V9qPbQ8Athpfp13+UcotvEBGxv8n ITdA4Tz3WmFZiQZ8jjyf3DEWdeIqfoZuOxw4ZngvHRlQsVr8ozQ72Oz8dPAp9Yt0GXGamp6mQUrn0 A8e5TFsmNIJw3jsA8m3m+9l+ExpdOwV6Rm3vwaSTWfOd6+35ZKn8E6emZDr4qe0XZ8EcMpfxVmjSK ISE83mStJ+f3JO4UUalHIoU+/3gEa9kw==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Wed, 8 Feb 2023 12:46:42 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <DUhjrp8d6_N.A.ZwE.xm54jB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5344-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
February 08, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : heimdal
CVE ID : CVE-2022-45142
Debian Bug : 1030849
Helmut Grohne discovered a flaw in Heimdal, an implementation of
Kerberos 5 that aims to be compatible with MIT Kerberos. The backports
of fixes for CVE-2022-3437 accidentally inverted important memory
comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check
handlers for gssapi, resulting in incorrect validation of message
integrity codes.
For the stable distribution (bullseye), this problem has been fixed in
version 7.7.0+dfsg-2+deb11u3.
We recommend that you upgrade your heimdal packages.
For the detailed security status of heimdal please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/heimdal
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmPjmWZfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Rw+RAAjSGizyQ7+71isP3z4Wtj8ZB1JMAjy+x8VfHL5F9Fh6ufV27fiH8WzrAo
dm4JHFwVRuEYby9JLl0DiHPffwx76TG61/TGLpGR5wcOeB9d7I/WZ5eNm92qEMCg
Q4sWpQRmD9L3TvKHoQV088yUUZYhkFedB2GbmabTBwa71FJ089ccvZX/ZvQVBvp/
QfFl1IgnNjkkRLdVQxUtMdgvxhkgkGC+gmLT/QxNcGXQX0/joVhw9vhKZahcP1er
1nQ34JEyNxogjuBHLCerMvwrJ4wHDLVg0luw8uuCK/hc4q8NxjNzty4ANAk0z6w4
9X4xJjf7LIHU/lNq25GtY6g9llSIhGVF1W92iPUuh6tTC99/qgmghVfx4Q+GZS+C
Sfnm23Aj+gXPzhBgcCeeWhzLT8idsk0RsJHAUI7Se/YCU/JnwunwS2LGuDiwO4e9
GdQyTY5jN0a/9K7nl3g6l+VZbEvoHlqdbJIOZGckUlwQRpiMRBMvKKXj8sF4a9TW
bcKOjUzp9TPDbtsfEBOrnUHnkar87aBliaWSr4uE320+9rPpgycSBwViAHnuC1ay
XGSiNmKaAYGyKdHWCPuawpVnPiCTQ+dVQuEw48uvLfgHf97Erdw919XRrKiyDtEG
hWTtki4dF9jWIESk9ba/bIavk7emo3Tny5h6PS1l/MV8Ior6S7k=
=naJG
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5344-1] heimdal security update, Salvatore Bonaccorso, 08.02.2023
Archiv bereitgestellt durch MHonArc 2.6.24.