Debian Package Tracker
Register | Log in
Subscribe

krb5

Choose email to subscribe with

general
  • source: krb5 (main)
  • version: 1.21.3-5
  • maintainer: Sam Hartman (DMD)
  • uploaders: Benjamin Kaduk [DMD] – Russ Allbery [DMD]
  • arch: all any
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.17-3+deb10u4
  • o-o-sec: 1.17-3+deb10u6
  • oldstable: 1.18.3-6+deb11u5
  • old-sec: 1.18.3-6+deb11u6
  • old-p-u: 1.18.3-6+deb11u5
  • stable: 1.20.1-2+deb12u3
  • stable-sec: 1.20.1-2+deb12u2
  • testing: 1.21.3-5
  • unstable: 1.21.3-5
versioned links
  • 1.17-3+deb10u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.17-3+deb10u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.18.3-6+deb11u5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.18.3-6+deb11u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.20.1-2+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.20.1-2+deb12u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.21.3-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • krb5-admin-server (4 bugs: 0, 3, 1, 0)
  • krb5-doc (2 bugs: 0, 1, 1, 0)
  • krb5-gss-samples
  • krb5-k5tls
  • krb5-kdc
  • krb5-kdc-ldap (1 bugs: 0, 1, 0, 0)
  • krb5-kpropd
  • krb5-locales
  • krb5-multidev (1 bugs: 0, 0, 1, 0)
  • krb5-otp
  • krb5-pkinit
  • krb5-user (3 bugs: 0, 1, 2, 0)
  • libgssapi-krb5-2 (3 bugs: 0, 3, 0, 0)
  • libgssrpc4t64
  • libk5crypto3 (1 bugs: 0, 1, 0, 0)
  • libkadm5clnt-mit12
  • libkadm5srv-mit12
  • libkdb5-10t64
  • libkrad-dev
  • libkrad0
  • libkrb5-3 (3 bugs: 0, 2, 1, 0)
  • libkrb5-dbg
  • libkrb5-dev (2 bugs: 0, 1, 1, 0)
  • libkrb5support0 (1 bugs: 0, 1, 0, 0)
action needed
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2025-3576: A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
Created: 2025-04-15 Last update: 2025-05-17 14:34
lintian reports 8 errors and 14 warnings high
Lintian reports 8 errors and 14 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2024-07-06 Last update: 2025-03-13 21:31
5 security issues in buster high

There are 5 open security issues in buster.

2 important issues:
  • CVE-2024-37370: In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
  • CVE-2024-37371: In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
3 issues postponed or untriaged:
  • CVE-2024-26458: (needs triaging) Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
  • CVE-2024-26461: (needs triaging) Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
  • CVE-2024-26462: (needs triaging) Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
Created: 2024-06-27 Last update: 2024-06-29 05:38
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2025-01-06 Last update: 2025-05-19 14:32
debian/patches: 13 patches to forward upstream low

Among the 13 debian patches available in version 1.21.3-5 of the package, we noticed the following issues:

  • 13 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2025-03-13 16:31
Build log checks report 1 warning low
Build log checks report 1 warning
Created: 2025-01-16 Last update: 2025-01-16 23:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-03-13 10:33
news
[rss feed]
  • [2025-04-14] Accepted krb5 1.20.1-2+deb12u3 (source) into proposed-updates (Debian FTP Masters) (signed by: Bastien ROUCARIÈS)
  • [2025-03-15] krb5 1.21.3-5 MIGRATED to testing (Debian testing watch)
  • [2025-03-13] Accepted krb5 1.21.3-5 (source) into unstable (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2025-02-23] Accepted krb5 1.18.3-6+deb11u6 (source) into oldstable-security (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2025-01-29] krb5 1.21.3-4 MIGRATED to testing (Debian testing watch)
  • [2025-01-16] Accepted krb5 1.21.3-4 (source) into unstable (Sam Hartman)
  • [2024-07-29] krb5 1.21.3-3 MIGRATED to testing (Debian testing watch)
  • [2024-07-08] Accepted krb5 1.20.1-2+deb12u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Sam Hartman)
  • [2024-07-07] Accepted krb5 1.18.3-6+deb11u5 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Sam Hartman)
  • [2024-07-05] Accepted krb5 1.18.3-6+deb11u5 (source) into oldstable-security (Debian FTP Masters) (signed by: Sam Hartman)
  • [2024-07-05] Accepted krb5 1.20.1-2+deb12u2 (source) into stable-security (Debian FTP Masters) (signed by: Sam Hartman)
  • [2024-07-05] Accepted krb5 1.21.3-3 (source) into unstable (Sam Hartman)
  • [2024-07-04] Accepted krb5 1.21.3-2 (source) into unstable (Sam Hartman)
  • [2024-06-27] Accepted krb5 1.21.3-1 (source) into unstable (Sam Hartman)
  • [2024-06-22] krb5 1.21.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-18] Accepted krb5 1.21.2-1 (source) into unstable (Sam Hartman)
  • [2024-05-03] krb5 1.20.1-6 MIGRATED to testing (Debian testing watch)
  • [2024-03-11] Accepted krb5 1.20.1-6 (source) into unstable (Sam Hartman)
  • [2024-02-28] Accepted krb5 1.20.1-5.1 (source) into unstable (Lukas Märdian)
  • [2024-02-17] Accepted krb5 1.20.1-5.1~exp1 (source) into experimental (Steve Langasek)
  • [2023-10-28] krb5 1.20.1-5 MIGRATED to testing (Debian testing watch)
  • [2023-10-24] Accepted krb5 1.20.1-5 (source) into unstable (Helmut Grohne) (signed by: Sam Hartman)
  • [2023-10-22] Accepted krb5 1.17-3+deb10u6 (source) into oldoldstable (Adrian Bunk)
  • [2023-09-23] krb5 1.20.1-4 MIGRATED to testing (Debian testing watch)
  • [2023-09-14] Accepted krb5 1.20.1-4 (source) into unstable (Sam Hartman)
  • [2023-08-19] Accepted krb5 1.18.3-6+deb11u4 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Sam Hartman)
  • [2023-08-19] Accepted krb5 1.20.1-2+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Sam Hartman)
  • [2023-08-17] krb5 1.20.1-3 MIGRATED to testing (Debian testing watch)
  • [2023-08-14] Accepted krb5 1.20.1-3 (source) into unstable (Sam Hartman)
  • [2023-05-24] krb5 1.20.1-2 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 31 32
  • RC: 0
  • I&N: 17 18
  • M&W: 14
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (8, 14)
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • l10n (100, 100)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.21.3-4ubuntu2
  • 30 bugs (2 patches)
  • patches for 1.21.3-4ubuntu2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing