PublicDateAtUSN: 2015-11-08 Candidate: CVE-2015-2695 PublicDate: 2015-11-09 03:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2695 https://ubuntu.com/security/notices/USN-2810-1 Description: lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=803083 http://krbdev.mit.edu/rt/Ticket/Display.html?id=8244 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: Patches_krb5: upstream: https://github.com/krb5/krb5/commit/b51b33f2bc5d1497ddf5bd107f791c101695000d upstream: https://github.com/krb5/krb5/commit/222b09f6e2f536354555f2a0dedfe29fc10c01d6 (regression fix) upstream_krb5: released (1.13.2+dfsg-3) precise_krb5: released (1.10+dfsg~beta1-2ubuntu0.7) trusty_krb5: released (1.12+dfsg-2ubuntu5.2) trusty/esm_krb5: released (1.12+dfsg-2ubuntu5.2) vivid_krb5: released (1.12.1+dfsg-18ubuntu0.1) wily_krb5: released (1.13.2+dfsg-2ubuntu0.1) devel_krb5: not-affected (1.13.2+dfsg-3) vivid/stable-phone-overlay_krb5: released (1.12.1+dfsg-18ubuntu0.1) vivid/ubuntu-core_krb5: released (1.12.1+dfsg-18ubuntu0.1)