Conectiva Information for VU#686862

MIT Kerberos 5 krb5_aname_to_localname() contains several heap overflows

Status

Affected

Vendor Statement

We are currently testing updated kerberos packages for Conectiva Linux 8 and Conectiva Linux 9. They will be made available at http://distro2.conectiva.com.br/atualizacoes/ shortly.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References

None

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.