{"id":"MGASA-2015-0446","summary":"Updated krb5 packages fix CVE-2015-2698","details":"Updated krb5 packages fix security vulnerabilities:\n\nIn any MIT krb5 release with the patches for CVE-2015-2696 applied, an\napplication which calls gss_export_sec_context() may experience memory\ncorruption if the context was established using the IAKERB mechanism.\nHistorically, some vulnerabilities of this nature can be translated\ninto remote code execution, though the necessary exploits must be\ntailored to the individual application and are usually quite\ncomplicated (CVE-2015-2698).\n","modified":"2026-04-16T06:22:28.444514677Z","published":"2015-11-16T21:36:58Z","upstream":["CVE-2015-2698"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0446.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17116"},{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2015-0436.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2015-November/171079.html"}],"affected":[{"package":{"name":"krb5","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/krb5?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.2-8.2.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0446.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}