-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 17 Nov 2022 12:41:46 -0700 Source: krb5 Architecture: source Version: 1.18.3-6+deb11u3 Distribution: bullseye-security Urgency: high Maintainer: Sam Hartman <hartmans@debian.org> Changed-By: Sam Hartman <hartmans@debian.org> Closes: 1024267 Changes: krb5 (1.18.3-6+deb11u3) bullseye-security; urgency=high . * Integer overflows in PAC parsing; potentially critical for 32-bit KDCs or when cross-realm acts maliciously; DOS in other conditions; CVE-2022-42898, Closes: #1024267 Checksums-Sha1: 4563ee77b2b1f9f687870218a3f120185f87d521 3209 krb5_1.18.3-6+deb11u3.dsc fdbb31fab5bdea24fc464d09bdbc245740648f1a 8715312 krb5_1.18.3.orig.tar.gz 909b9c68601cf999cd2697c83a0f56efd0faba6d 833 krb5_1.18.3.orig.tar.gz.asc 3fb20afe28c1028005895e089327aa9b42d8572a 108804 krb5_1.18.3-6+deb11u3.debian.tar.xz 765dda2737715a73f4257f36aa23709d6dbfea6b 5299 krb5_1.18.3-6+deb11u3_source.buildinfo Checksums-Sha256: 539d8a8df5c181b5c16cab487fef4d192f934a170dcfe507e76020132fdb5399 3209 krb5_1.18.3-6+deb11u3.dsc e61783c292b5efd9afb45c555a80dd267ac67eebabca42185362bee6c4fbd719 8715312 krb5_1.18.3.orig.tar.gz ded19808ba7320ad0bb3ddfb5202845b2ff36a50613af7832f78dd3cb4437419 833 krb5_1.18.3.orig.tar.gz.asc 5efc82324430be1c2e12a6f0b40dd27b149f5f77cfe10a9ed0b8567a07f08981 108804 krb5_1.18.3-6+deb11u3.debian.tar.xz 010da2ea85740fd7c3aa006e18737aac611036e763369cea85bd0e2655d6204a 5299 krb5_1.18.3-6+deb11u3_source.buildinfo Files: bf71dfd670a582099641ffe284d25c3c 3209 net optional krb5_1.18.3-6+deb11u3.dsc a64e8018a7572e0b4bd477c745129ffc 8715312 net optional krb5_1.18.3.orig.tar.gz bca804e12e8dc2de6930e916cd7a2ce3 833 net optional krb5_1.18.3.orig.tar.gz.asc 2f8366885ca14a369e53dfa6290d70a5 108804 net optional krb5_1.18.3-6+deb11u3.debian.tar.xz 85ac8d7fcd056cc14c9fdeaf27049b10 5299 net optional krb5_1.18.3-6+deb11u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQSj2jRwbAdKzGY/4uAsbEw8qDeGdAUCY3edjAAKCRAsbEw8qDeG dMeHAPwMg8/Dx2M51bFuxWo2fE/1mokrUxL7e0oJgdxNICXJwwEA2yTWOhMdTupp U/WQkuML2jqLSLDIek4IjsAEo0N0OgQ= =cMjT -----END PGP SIGNATURE-----