Bug 146939 - security/krb5: krb5-1.8.1 security vulnerability
Summary: security/krb5: krb5-1.8.1 security vulnerability
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Cy Schubert
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-05-25 05:10 UTC by Garrett Wollman
Modified: 2010-05-25 06:20 UTC (History)
0 users

See Also:


Attachments
file.diff (1.62 KB, patch)
2010-05-25 05:10 UTC, Garrett Wollman
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Garrett Wollman 2010-05-25 05:10:01 UTC
security/krb5 has a security problem, described in a recent advisory
(and noted by portaudit).

Fix: Here's a (probably poorly-styled) patch.  Note that the portaudit
source file needs to be fixed as well to tell it that 1.8.1_1 has the
bug fixed.  You should verify the PGP signature for the patch
yourself.
How-To-Repeat: 
# portupgrade krb5
watch it fail
watch portupgrade fail to notice that it failed and delete the
installed krb5 package anyway
Comment 1 Mark Linimon freebsd_committer freebsd_triage 2010-05-25 05:31:28 UTC
Responsible Changed
From-To: freebsd-ports-bugs->cy

Fix synopsis and assign.
Comment 2 Cy Schubert freebsd_committer freebsd_triage 2010-05-25 06:10:41 UTC
State Changed
From-To: open->closed

Committed. Thanks Garrett.
Comment 3 dfilter service freebsd_committer freebsd_triage 2010-05-25 06:14:29 UTC
cy          2010-05-25 05:14:16 UTC

  FreeBSD ports repository

  Modified files:
    security/krb5        Makefile distinfo 
  Log:
  Apply patch for MIT KRB5 security vulnerability MITKRB5-SA-2010-005.
  
  PR:             146939
  Submitted by:   wollman
  Security:       MIT krb5 Security Advisory 2010-005
  
  Revision  Changes    Path
  1.139     +3 -1      ports/security/krb5/Makefile
  1.41      +3 -0      ports/security/krb5/distinfo
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"