Fedora 40: krb5 2024-29a74ac2b0 Security Advisory Updates
Summary
Kerberos V5 is a trusted-third-party network authentication system,
which can improve your network's security by eliminating the insecure
practice of sending passwords over the network in unencrypted form.
Update Information:
Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the "RSA" method for PKINIT Fix of miscellaneous mistakes in the code Enhancement: Rework of TCP request timeout (disabled by default, global timeout setting added)
Change Log
* Wed Oct 30 2024 Julien Rische
References
[ 1 ] Bug #2304071 - libkrad: implement support for Message-Authenticator (CVE-2024-3596)
https://bugzilla.redhat.com/show_bug.cgi?id=2304071
[ 2 ] Bug #2322704 - Fix various issues detected by static analysis
https://bugzilla.redhat.com/show_bug.cgi?id=2322704
[ 3 ] Bug #2322706 - Remove RSA protocol for PKINIT
https://bugzilla.redhat.com/show_bug.cgi?id=2322706
[ 4 ] Bug #2322711 - Make TCP waiting time configurable
https://bugzilla.redhat.com/show_bug.cgi?id=2322711
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-29a74ac2b0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label