-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 01 Jul 2024 11:31:35 -0600 Source: krb5 Binary: krb5-doc krb5-locales Architecture: all Version: 1.20.1-2+deb12u2 Distribution: bookworm-security Urgency: high Maintainer: amd64 Build Daemon (x86-grnet-03) Changed-By: Sam Hartman Description: krb5-doc - documentation for MIT Kerberos krb5-locales - internationalization support for MIT Kerberos Changes: krb5 (1.20.1-2+deb12u2) bookworm-security; urgency=high . * CVE-2024-37370: an unauthenticated attacker can modify the extra count in an RFC 4121 GSS token, causing the token to appear truncated. * CVE-2024-37371: an attacker can cause invalid memory reads by sending an invalid GSS token. Checksums-Sha1: efbc366447ab78130c14cc478f1bc7cf2fbba0b6 2790344 krb5-doc_1.20.1-2+deb12u2_all.deb 0ed8dfa0518cb01d221b8ac54265afd759235d48 62820 krb5-locales_1.20.1-2+deb12u2_all.deb 6b0736ceb5de5192a9b9931b271103c934ea60ea 11853 krb5_1.20.1-2+deb12u2_all-buildd.buildinfo Checksums-Sha256: 862f45a63dbbc8c4551e22f5da15054dfebc5674e6bb36afc42dc40fbe9242c7 2790344 krb5-doc_1.20.1-2+deb12u2_all.deb cc758a92d31d334a393e328308c1865710dd6a17642af1d1ff03af57444a9160 62820 krb5-locales_1.20.1-2+deb12u2_all.deb dda01481872baf101397208468448d27186e674063469f336d8a5d5cae0ff768 11853 krb5_1.20.1-2+deb12u2_all-buildd.buildinfo Files: 9f1c1312cf871c770105ef57b47fb997 2790344 doc optional krb5-doc_1.20.1-2+deb12u2_all.deb cf2833e70f6c1255048ccf49a8c16304 62820 localization optional krb5-locales_1.20.1-2+deb12u2_all.deb d507f74e2b4b96cbdda4088fcedec06e 11853 net optional krb5_1.20.1-2+deb12u2_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEe8x49oT2k+seQstpgDm7h4zfCpIFAmaDB54ACgkQgDm7h4zf CpKcyxAAmC14i+yRYzmrnpwDRgkOtJ7sqGc1oI4oAl3S6k4GVlr83bJqbIpdkCNb 8UBfjQwjUQHDLA//3PMcchjfJV7eh7CLsFeTI58qfBnAmfwNr4YwHKpuKMpEqjaS ofBuRIRt8RD7odYwadrHDURdYVDV6Q1YJeuJ4ssAA0gdDMBi+4DoamNRWzVUG0ty W4gH3VrmYqY4HEajgbhnXLKcAD7CMm7+J50WhAdXSUfKoe3wrhVZf7sRauDkFxJl k3DDDHuw1QJqTXCzHmY5hnHJNNZ1L7dr6vVhGDmzTJui/5WUXDCS0ot6YHaVjk+9 JmeR6d2fVfYmYftoRgcZjNi/f7+4lO3EFOeZ6THazAHO8LEELx32kmexer5DbCXi NPpzVN5i8mSQvk0KB84YvVzO3Ioew9LndYoeLU+bxUVQhz+EozV3ROzglkDlQ+p6 qnTQcscaHmNQEF19TQQhWYKd5KIUBF27oKIFRx0jsAe6mjI+skXalAwv9Rr1GaX8 C5XxUzjCamReiF8OVHyFj4UvLOOADueSD0/uAheFCqeTB93ftLMGaGhZVWbypWIh FGkB9xlHxtLYY7o6ZNXEI4/aSNk96L7G3M6S9zxjTe5rmlgBFjIOXBQU4xh+1I+m YhnH7NWCtFUbf/O30XxaW0Msi6QA9YjiRGCJaQo+8H4n3A77kb0= =P28y -----END PGP SIGNATURE-----