[ubuntu/jammy-updates] krb5 1.19.2-2ubuntu0.5 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Wed Feb 5 06:14:21 UTC 2025


krb5 (1.19.2-2ubuntu0.5) jammy-security; urgency=medium

  * SECURITY UPDATE: Use of MD5-based message authentication over plaintext
    communications could lead to forgery attacks.
    - debian/patches/CVE-2024-3596.patch: Secure Response Authenticator
      by adding support for the Message-Authenticator attribute in non-EAP
      authentication methods.
    - CVE-2024-3596
  * Update libk5crypto3 symbols: add k5_hmac_md5 symbol.

Date: 2025-02-04 15:58:27.406668+00:00
Changed-By: nicolas campuzano jimenez <nicolas.campuzano at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.5
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list