ELA-308-1 krb5 security update

denial-of-service vulnerability

2020-11-07
Packagekrb5
Version1.12.1+dfsg-19+deb8u6
Related CVEs CVE-2020-28196


It was discovered that there was a denial of service vulnerability in the MIT Kerberos network authentication system, krb5. The lack of a limit in the “ASN.1” decoder could lead to infinite recursion and allow an attacker to overrun the stack and cause the process to crash.



For Debian 8 Jessie, these problems have been fixed in version 1.12.1+dfsg-19+deb8u6.

We recommend that you upgrade your krb5 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.