Bug 770172 (CVE-2012-1014) - VUL-0: CVE-2012-1014 CVE-2012-1015: krb5: MITKRB5-SA-2012-001: crash/potentially execute code flaws
Summary: VUL-0: CVE-2012-1014 CVE-2012-1015: krb5: MITKRB5-SA-2012-001: crash/potentia...
Status: RESOLVED FIXED
Alias: CVE-2012-1014
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Critical
Target Milestone: ---
Assignee: Howard Guo
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:SUSE:CVE-2012-1015:5.0:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2012-07-06 07:04 UTC by Marcus Meissner
Modified: 2017-12-11 13:34 UTC (History)
7 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
patch for krb5-1.10 (2.39 KB, patch)
2012-07-28 13:52 UTC, Michael Calmer
Details | Diff
patch for krb5-1.8 (1.74 KB, patch)
2012-07-28 13:52 UTC, Michael Calmer
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Comment 2 Marcus Meissner 2012-07-06 07:05:46 UTC
As it affects 1.8 / 1.10 or later, I think SLES 11 and older are not affected,
only openSUSE is.

So nothing to prepare until the CRD of July 31st.
Comment 3 Swamp Workflow Management 2012-07-06 22:00:09 UTC
bugbot adjusting priority
Comment 5 Michael Calmer 2012-07-28 13:52:28 UTC
Created attachment 500342 [details]
patch for krb5-1.10
Comment 6 Michael Calmer 2012-07-28 13:52:59 UTC
Created attachment 500343 [details]
patch for krb5-1.8
Comment 7 Michael Calmer 2012-08-01 08:53:09 UTC
Bug is public now.

I have created a maintenance request for openSUSE (hopefully I did it right - maybe somebody can check it)

Re-assign to security team for tracking.
Comment 8 Marcus Meissner 2012-08-01 12:30:29 UTC
looked good, thanks!
Comment 9 Swamp Workflow Management 2012-08-08 12:08:49 UTC
openSUSE-SU-2012:0967-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 770172
CVE References: CVE-2012-1014,CVE-2012-1015
Sources used:
openSUSE 12.1 (src):    krb5-1.9.1-24.9.1
openSUSE 11.4 (src):    krb5-1.8.3-52.1
Comment 10 Marcus Meissner 2012-08-13 13:09:00 UTC
danke!
Comment 22 Johannes Segitz 2017-12-11 13:34:54 UTC
should be done