News for package krb5

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 3.0 (quilt)
Source: krb5
Binary: krb5-user, krb5-kdc, krb5-kdc-ldap, krb5-admin-server, krb5-multidev, libkrb5-dev, libkrb5-dbg, krb5-pkinit, krb5-otp, krb5-k5tls, krb5-doc, libkrb5-3, libgssapi-krb5-2, libgssrpc4, libkadm5srv-mit9, libkadm5clnt-mit9, libk5crypto3, libkdb5-8, libkrb5support0, libkrad0, krb5-gss-samples, krb5-locales, libkrad-dev
Architecture: any all
Version: 1.13.2+dfsg-3
Maintainer: Sam Hartman <[email protected]>
Uploaders: Russ Allbery <[email protected]>, Benjamin Kaduk <[email protected]>
Homepage: http://web.mit.edu/kerberos/
Standards-Version: 3.9.6
Vcs-Browser: http://git.debian.org/?p=pkg-k5-afs/debian-krb5-2013.git
Vcs-Git: git://git.debian.org/git/pkg-k5-afs/debian-krb5-2013.git
Build-Depends: debhelper (>= 8.1.3), byacc | bison, comerr-dev, docbook-to-man, doxygen, libkeyutils-dev [linux-any], libldap2-dev, libncurses5-dev, libssl-dev, ss-dev, libverto-dev (>= 0.2.4), pkg-config, dh-systemd
Build-Depends-Indep: python, python-cheetah, python-lxml, python-sphinx, doxygen-latex
Package-List:
 krb5-admin-server deb net optional arch=any
 krb5-doc deb doc optional arch=all
 krb5-gss-samples deb net extra arch=any
 krb5-k5tls deb net extra arch=any
 krb5-kdc deb net optional arch=any
 krb5-kdc-ldap deb net extra arch=any
 krb5-locales deb localization standard arch=all
 krb5-multidev deb libdevel optional arch=any
 krb5-otp deb net extra arch=any
 krb5-pkinit deb net extra arch=any
 krb5-user deb net optional arch=any
 libgssapi-krb5-2 deb libs standard arch=any
 libgssrpc4 deb libs standard arch=any
 libk5crypto3 deb libs standard arch=any
 libkadm5clnt-mit9 deb libs standard arch=any
 libkadm5srv-mit9 deb libs standard arch=any
 libkdb5-8 deb libs standard arch=any
 libkrad-dev deb libdevel extra arch=any
 libkrad0 deb libs standard arch=any
 libkrb5-3 deb libs standard arch=any
 libkrb5-dbg deb debug extra arch=any
 libkrb5-dev deb libdevel extra arch=any
 libkrb5support0 deb libs standard arch=any
Checksums-Sha1:
 2de0f519bb7c51612e2816a9dc64d966ac6e97b2 11884064 krb5_1.13.2+dfsg.orig.tar.gz
 25217c2d8d7e861cae4bbdd02f162219456b0a4f 97508 krb5_1.13.2+dfsg-3.debian.tar.xz
Checksums-Sha256:
 a7af3953e4ab52b17f80bdfc2fc7471b66b512b128520796e2b993554543873a 11884064 krb5_1.13.2+dfsg.orig.tar.gz
 e8e85c58bc31a07b5fec1c06b1bf4ea28020cc253b3af050742f323fc7606494 97508 krb5_1.13.2+dfsg-3.debian.tar.xz
Files:
 b9b16449b2e584a7360cdeed12687484 11884064 krb5_1.13.2+dfsg.orig.tar.gz
 9283eb3d3b62b016975a9e123d146341 97508 krb5_1.13.2+dfsg-3.debian.tar.xz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQGgBAEBCgAGBQJWLmyOAAoJECjZpvNk63USCe0MH2ZApuK95lfjRX+DVNs+2g8+
Rkn523pICIIVGzlOdCCPWO0Wc/Kue3itmPzZZuT2mSNgjdh0YFhMSe4zutx+q2Uc
xuapcNbjQIjgPXV6G2jrixFtN3iYdLwJw5wAvSGycxOEf/krwnUhQYJ+R9qDctSr
7OJSAZ42WtN1Wx2+ILfEZ6YxAm74uK4jezf7RYKnEo9yqpFCe6tD1l8mlnmTA4WY
rz1RhzesPr2LRS4cKfRQD4QKol5HzHXRjSwbyQV/Mzesk8I9aNywKeJbJCSfbY79
5A5t6IC04SoJBgxQPNBiqjhatSXThmTo1mku4CQ00bQ8oVD0Cax8E8crrg3mvMvu
GmRawAoEl6XcdC5FOS6qUgaCS0WSZKo2XmyDwoG238NbPj6wUGZUtxI9HZ1voUv6
wsTKukftvK4l/2M57eSurmRktaRSpp07dYCGAM6FZhZ3WkhcL+evjP9srnkqhpgw
ETz2YCgLS01Bl/6aUH7LbdUBz/WKpm99yQl9QgBAaLR94io=
=HYyu
-----END PGP SIGNATURE-----

Changes:
krb5 (1.13.2+dfsg-3) unstable; urgency=high

  * Import upstream patches for three CVEs:
    - CVE-2015-2695: SPNEGO context aliasing during establishment
    - CVE-2015-2696: IAKERB context aliasing during establishment
    - CVE-2015-2697: unsafe string handling in TGS processing

 -- Benjamin Kaduk <[email protected]>  Mon, 26 Oct 2015 14:03:52 -0400