Описание
Security update for krb5
This update for krb5 fixes the following issues:
- CVE-2024-37370: Fixed confidential GSS krb5 wrap tokens with invalid fields were errouneously accepted (bsc#1227186).
- CVE-2024-37371: Fixed invalid memory read when processing message tokens with invalid length fields (bsc#1227187).
Список пакетов
Container bci/bci-init:15.7
krb5-1.20.1-150600.11.3.1
Container bci/bci-init:latest
krb5-1.20.1-150600.11.3.1
Container bci/bci-sle15-kernel-module-devel:15.7
krb5-1.20.1-150600.11.3.1
Container bci/bci-sle15-kernel-module-devel:latest
krb5-1.20.1-150600.11.3.1
Container bci/gcc:latest
krb5-1.20.1-150600.11.3.1
Container bci/golang:1.22-openssl
krb5-1.20.1-150600.11.3.1
Container bci/golang:1.23
krb5-1.20.1-150600.11.3.1
Container bci/golang:latest
krb5-1.20.1-150600.11.3.1
Container bci/kiwi:latest
krb5-1.20.1-150600.11.3.1
Container bci/node:22
krb5-1.20.1-150600.11.3.1
Container bci/nodejs:latest
krb5-1.20.1-150600.11.3.1
Container bci/openjdk-devel:17
krb5-1.20.1-150600.11.3.1
Container bci/openjdk-devel:latest
krb5-1.20.1-150600.11.3.1
Container bci/openjdk:17
krb5-1.20.1-150600.11.3.1
Container bci/openjdk:latest
krb5-1.20.1-150600.11.3.1
Container bci/php-apache:latest
krb5-1.20.1-150600.11.3.1
Container bci/php-fpm:latest
krb5-1.20.1-150600.11.3.1
Container bci/php:latest
krb5-1.20.1-150600.11.3.1
Container bci/python:3
krb5-1.20.1-150600.11.3.1
Container bci/python:3.13
krb5-1.20.1-150600.11.3.1
Container bci/python:latest
krb5-1.20.1-150600.11.3.1
Container bci/ruby:3
krb5-1.20.1-150600.11.3.1
Container bci/ruby:latest
krb5-1.20.1-150600.11.3.1
Container bci/rust:1.84
krb5-1.20.1-150600.11.3.1
Container bci/rust:latest
krb5-1.20.1-150600.11.3.1
Container bci/spack:0.23
krb5-1.20.1-150600.11.3.1
Container bci/spack:latest
krb5-1.20.1-150600.11.3.1
Container containers/apache-pulsar:3.3
krb5-1.20.1-150600.11.3.1
Container containers/apache-tomcat:10.1-openjdk11
krb5-1.20.1-150600.11.3.1
Container containers/apache-tomcat:10.1-openjdk17
krb5-1.20.1-150600.11.3.1
Container containers/apache-tomcat:10.1-openjdk21
krb5-1.20.1-150600.11.3.1
Container containers/apache-tomcat:9-openjdk11
krb5-1.20.1-150600.11.3.1
Container containers/apache-tomcat:9-openjdk17
krb5-1.20.1-150600.11.3.1
Container containers/apache-tomcat:9-openjdk21
krb5-1.20.1-150600.11.3.1
Container containers/apache-tomcat:9-openjdk8
krb5-1.20.1-150600.11.3.1
Container containers/milvus:2.4
krb5-1.20.1-150600.11.3.1
Container containers/ollama:0
krb5-1.20.1-150600.11.3.1
Container containers/open-webui:0
krb5-1.20.1-150600.11.3.1
Container containers/python:3.11
krb5-1.20.1-150600.11.3.1
Container containers/python:3.9
krb5-1.20.1-150600.11.3.1
Container containers/pytorch:2-nvidia
krb5-1.20.1-150600.11.3.1
Container containers/pytorch:2.5.0
krb5-1.20.1-150600.11.3.1
Container suse/389-ds:latest
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Container suse/git:latest
krb5-1.20.1-150600.11.3.1
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
krb5-1.20.1-150600.11.3.1
Container suse/manager/5.0/x86_64/proxy-httpd:latest
krb5-1.20.1-150600.11.3.1
Container suse/manager/5.0/x86_64/proxy-salt-broker:latest
krb5-1.20.1-150600.11.3.1
Container suse/manager/5.0/x86_64/proxy-squid:latest
krb5-1.20.1-150600.11.3.1
Container suse/manager/5.0/x86_64/proxy-ssh:latest
krb5-1.20.1-150600.11.3.1
Container suse/manager/5.0/x86_64/proxy-tftpd:latest
krb5-1.20.1-150600.11.3.1
Container suse/manager/5.0/x86_64/server-hub-xmlrpc-api:latest
krb5-1.20.1-150600.11.3.1
Container suse/manager/5.0/x86_64/server-migration-14-16:latest
krb5-1.20.1-150600.11.3.1
Container suse/manager/5.0/x86_64/server:latest
krb5-1.20.1-150600.11.3.1
Container suse/mariadb-client:latest
krb5-1.20.1-150600.11.3.1
Container suse/mariadb:latest
krb5-1.20.1-150600.11.3.1
Container suse/nginx:latest
krb5-1.20.1-150600.11.3.1
Container suse/pcp:latest
krb5-1.20.1-150600.11.3.1
Container suse/postgres:16
krb5-1.20.1-150600.11.3.1
Container suse/postgres:latest
krb5-1.20.1-150600.11.3.1
Container suse/registry:latest
krb5-1.20.1-150600.11.3.1
Container suse/rmt-server:latest
krb5-1.20.1-150600.11.3.1
Container suse/sle15:15.6
krb5-1.20.1-150600.11.3.1
Container suse/sle15:15.7
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/cdi-apiserver:1.58.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/cdi-cloner:1.58.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/cdi-controller:1.58.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/cdi-importer:1.58.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/cdi-operator:1.58.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/cdi-uploadproxy:1.58.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/cdi-uploadserver:1.58.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/libguestfs-tools:1.4.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/virt-api:1.4.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/virt-controller:1.4.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/virt-exportproxy:1.4.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/virt-exportserver:1.4.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/virt-handler:1.4.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/virt-launcher:1.4.0
krb5-1.20.1-150600.11.3.1
Container suse/sles/15.7/virt-operator:1.4.0
krb5-1.20.1-150600.11.3.1
Container suse/stunnel:latest
krb5-1.20.1-150600.11.3.1
Container trento/trento-wanda:latest
krb5-1.20.1-150600.11.3.1
Container trento/trento-web:latest
krb5-1.20.1-150600.11.3.1
Image SLES15-SP6
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-Azure-Basic
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-Azure-Standard
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-BYOS
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-BYOS-Azure
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-BYOS-EC2
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-BYOS-GCE
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-CHOST-BYOS
krb5-1.20.1-150600.11.3.1
Image SLES15-SP6-CHOST-BYOS-Aliyun
krb5-1.20.1-150600.11.3.1
Image SLES15-SP6-CHOST-BYOS-Azure
krb5-1.20.1-150600.11.3.1
Image SLES15-SP6-CHOST-BYOS-EC2
krb5-1.20.1-150600.11.3.1
Image SLES15-SP6-CHOST-BYOS-GCE
krb5-1.20.1-150600.11.3.1
Image SLES15-SP6-CHOST-BYOS-GDC
krb5-1.20.1-150600.11.3.1
Image SLES15-SP6-CHOST-BYOS-SAP-CCloud
krb5-1.20.1-150600.11.3.1
Image SLES15-SP6-EC2
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-EC2-ECS-HVM
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-GCE
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-HPC
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-HPC-Azure
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-HPC-BYOS
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-HPC-BYOS-Azure
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-HPC-BYOS-EC2
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-HPC-BYOS-GCE
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-HPC-EC2
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-HPC-GCE
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-Hardened-BYOS
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-Hardened-BYOS-Azure
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-Hardened-BYOS-EC2
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-Hardened-BYOS-GCE
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Azure
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Azure-LI-BYOS
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Azure-VLI-BYOS
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Azure-VLI-BYOS-Production
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-BYOS
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-BYOS-Azure
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-BYOS-EC2
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-BYOS-GCE
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-EC2
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-GCE
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Hardened
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Hardened-Azure
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Hardened-BYOS
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Hardened-BYOS-Azure
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Hardened-BYOS-EC2
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Hardened-BYOS-GCE
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Hardened-EC2
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAP-Hardened-GCE
krb5-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAPCAL
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAPCAL-Azure
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAPCAL-EC2
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image SLES15-SP6-SAPCAL-GCE
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
Image ai_15_6
krb5-1.20.1-150600.11.3.1
Image proxy-httpd-image
krb5-1.20.1-150600.11.3.1
Image proxy-salt-broker-image
krb5-1.20.1-150600.11.3.1
Image proxy-squid-image
krb5-1.20.1-150600.11.3.1
Image proxy-ssh-image
krb5-1.20.1-150600.11.3.1
Image proxy-tftpd-image
krb5-1.20.1-150600.11.3.1
Image python_15_6
krb5-1.20.1-150600.11.3.1
Image server-hub-xmlrpc-api-image
krb5-1.20.1-150600.11.3.1
Image server-image
krb5-1.20.1-150600.11.3.1
Image server-migration-14-16-image
krb5-1.20.1-150600.11.3.1
Image tomcat_15_6
krb5-1.20.1-150600.11.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
krb5-devel-1.20.1-150600.11.3.1
krb5-plugin-preauth-otp-1.20.1-150600.11.3.1
krb5-plugin-preauth-pkinit-1.20.1-150600.11.3.1
SUSE Linux Enterprise Module for Server Applications 15 SP6
krb5-plugin-kdb-ldap-1.20.1-150600.11.3.1
krb5-server-1.20.1-150600.11.3.1
openSUSE Leap 15.6
krb5-1.20.1-150600.11.3.1
krb5-32bit-1.20.1-150600.11.3.1
krb5-client-1.20.1-150600.11.3.1
krb5-devel-1.20.1-150600.11.3.1
krb5-devel-32bit-1.20.1-150600.11.3.1
krb5-plugin-kdb-ldap-1.20.1-150600.11.3.1
krb5-plugin-preauth-otp-1.20.1-150600.11.3.1
krb5-plugin-preauth-pkinit-1.20.1-150600.11.3.1
krb5-plugin-preauth-spake-1.20.1-150600.11.3.1
krb5-server-1.20.1-150600.11.3.1
Ссылки
- Link for SUSE-SU-2024:2307-1
- E-Mail link for SUSE-SU-2024:2307-1
- SUSE Security Ratings
- SUSE Bug 1227186
- SUSE Bug 1227187
- SUSE CVE CVE-2024-37370 page
- SUSE CVE CVE-2024-37371 page
Описание
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
Затронутые продукты
Container bci/bci-init:15.7:krb5-1.20.1-150600.11.3.1
Container bci/bci-init:latest:krb5-1.20.1-150600.11.3.1
Container bci/bci-sle15-kernel-module-devel:15.7:krb5-1.20.1-150600.11.3.1
Container bci/bci-sle15-kernel-module-devel:latest:krb5-1.20.1-150600.11.3.1
Ссылки
- CVE-2024-37370
- SUSE Bug 1227186
- SUSE Bug 1227187
Описание
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
Затронутые продукты
Container bci/bci-init:15.7:krb5-1.20.1-150600.11.3.1
Container bci/bci-init:latest:krb5-1.20.1-150600.11.3.1
Container bci/bci-sle15-kernel-module-devel:15.7:krb5-1.20.1-150600.11.3.1
Container bci/bci-sle15-kernel-module-devel:latest:krb5-1.20.1-150600.11.3.1
Ссылки
- CVE-2024-37371
- SUSE Bug 1227186
- SUSE Bug 1227187