Red Hat Inc. Information for VU#795632

MIT Kerberos 5 ASN.1 decoding functions insecurely deallocate memory (double-free)



Vendor Statement

New krb5 packages are now available along with our advisory at the URLs below and by using the Red Hat Network 'up2date' tool. Please note that Red Hat Enterprise Linux 3 contained a fix for VU#350792 (CAN-2004-0772) from release, and for Red Hat Enterprise Linux 2.1 users this issue was fixed in a previous update, RHSA-2003:052.