Re: MITKRB5-SA-2003-05: Buffer overrun and underrun in principal name handling

Ken Raeburn <[email protected]> Thu, 20 Mar 2003 16:47:22 -0500
Newsgroups gmane.comp.encryption.kerberos.announce
Message-ID <[email protected]>
This advisory has been updated on our web site.

The patch is now contained in a separate text file, with a separate
PGP signature available.

The advisory text now notes that it includes information also
published in the following vulnerability notes:

   CVE CAN-2003-0082

      Buffer underrun

   CVE CAN-2003-0072

      Array overrun -- only the portions that appeared to affect a server
      with no strange realm configurations were included here.

This announcement and related security advisories may be found on the
MIT Kerberos security advisory page at:

	http://web.mit.edu/kerberos/www/advisories/index.html

The main MIT Kerberos web page is at:

	http://web.mit.edu/kerberos/www/index.html

Ken

_______________________________________________
kerberos-announce mailing list
[email protected]
http://mailman.mit.edu/mailman/listinfo/kerberos-announce
signature.asc (application/pgp-signature, 231 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE+ejbuUqOaDMQ+e5gRAjykAJ9nEpeWOMrrwgyzKW5YlQxQhwLtZACfTbWW
tD55/KRSDIgDS5L25IoDgeY=
=D3ly
-----END PGP SIGNATURE-----