[oe] [PATCH 0/4][meta-oe] krb5: fix CVEs

wenzong.fan at windriver.com wenzong.fan at windriver.com
Sat Nov 14 10:22:25 UTC 2015


From: Wenzong Fan <wenzong.fan at windriver.com>

Fix CVEs:

  CVE-2015-2695
  CVE-2015-2696
  CVE-2015-2697
  CVE-2015-2698

The following changes since commit 721a2cabf352085d34dd14c22e71914d3429ca59:

  ntp: upgrade 4.2.8p3 -> 4.2.8p4 (2015-11-11 12:12:08 +0100)

are available in the git repository at:

  git://git.pokylinux.org/poky-contrib wenzong/krb5-new
  http://git.pokylinux.org/cgit.cgi/poky-contrib/log/?h=wenzong/krb5-new

Wenzong Fan (4):
  krb5: fix CVE-2015-2695
  krb5: fix CVE-2015-2696
  krb5: fix CVE-2015-2697
  krb5: fix CVE-2015-2698

 ...AKERB-context-aliasing-bugs-CVE-2015-2696.patch | 739 +++++++++++++++++++++
 ...AKERB-context-export-import-CVE-2015-2698.patch | 134 ++++
 ...PNEGO-context-aliasing-bugs-CVE-2015-2695.patch | 572 ++++++++++++++++
 ...-build_principal-memory-bug-CVE-2015-2697.patch |  58 ++
 meta-oe/recipes-connectivity/krb5/krb5_1.13.2.bb   |   4 +
 5 files changed, 1507 insertions(+)
 create mode 100644 meta-oe/recipes-connectivity/krb5/krb5/Fix-IAKERB-context-aliasing-bugs-CVE-2015-2696.patch
 create mode 100644 meta-oe/recipes-connectivity/krb5/krb5/Fix-IAKERB-context-export-import-CVE-2015-2698.patch
 create mode 100644 meta-oe/recipes-connectivity/krb5/krb5/Fix-SPNEGO-context-aliasing-bugs-CVE-2015-2695.patch
 create mode 100644 meta-oe/recipes-connectivity/krb5/krb5/Fix-build_principal-memory-bug-CVE-2015-2697.patch

-- 
1.9.1




More information about the Openembedded-devel mailing list