krb5 was updated to fix four security issues.
These security issues were fixed: - CVE-2014-5353: NULL pointer dereference when using a ticket policy name as password name (bsc#910457). - CVE-2014-5354: NULL pointer dereference when using keyless entries (bsc#910458). - CVE-2014-5355: Denial of service in krb5readmessage (bsc#918595). - CVE-2015-2694: OTP and PKINIT kdcpreauth modules leading to requires_preauth bypass (bsc#928978).
{
"binaries": [
{
"krb5-plugin-kdb-ldap": "1.12.1-16.1",
"krb5-plugin-preauth-otp": "1.12.1-16.1",
"krb5-plugin-preauth-pkinit": "1.12.1-16.1",
"krb5-client": "1.12.1-16.1",
"krb5": "1.12.1-16.1",
"krb5-server": "1.12.1-16.1",
"krb5-doc": "1.12.1-16.1",
"krb5-32bit": "1.12.1-16.1"
}
]
}{
"binaries": [
{
"krb5-plugin-kdb-ldap": "1.12.1-16.1",
"krb5-plugin-preauth-otp": "1.12.1-16.1",
"krb5-plugin-preauth-pkinit": "1.12.1-16.1",
"krb5-client": "1.12.1-16.1",
"krb5": "1.12.1-16.1",
"krb5-server": "1.12.1-16.1",
"krb5-doc": "1.12.1-16.1",
"krb5-32bit": "1.12.1-16.1"
}
]
}