Bugzilla – Bug 770172
VUL-0: CVE-2012-1014 CVE-2012-1015: krb5: MITKRB5-SA-2012-001: crash/potentially execute code flaws
Last modified: 2017-12-11 13:34:54 UTC
As it affects 1.8 / 1.10 or later, I think SLES 11 and older are not affected, only openSUSE is. So nothing to prepare until the CRD of July 31st.
bugbot adjusting priority
Created attachment 500342 [details] patch for krb5-1.10
Created attachment 500343 [details] patch for krb5-1.8
Bug is public now. I have created a maintenance request for openSUSE (hopefully I did it right - maybe somebody can check it) Re-assign to security team for tracking.
looked good, thanks!
openSUSE-SU-2012:0967-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 770172 CVE References: CVE-2012-1014,CVE-2012-1015 Sources used: openSUSE 12.1 (src): krb5-1.9.1-24.9.1 openSUSE 11.4 (src): krb5-1.8.3-52.1
danke!
should be done