Red Hat Bugzilla – Bug 1185770
Missing upstream test in krb5-1.12.2: src/tests/gssapi/t_invalid.c
Last modified: 2015-11-19 00:13:02 EST
Description of problem: The is upstream test for CVE-2014-4341 (src/tests/gssapi/t_invalid.c) is shipped on booth RHEL-5 and RHEL-6, but is missing on RHEL-7. Please include it also in this release. Version-Release number of selected component (if applicable): krb5-1.12.2-13.el7
Looks like will be fixed with planned rebase. $ ls krb5-1.13.1/src/tests/gssapi/t_invalid.c krb5-1.13.1/src/tests/gssapi/t_invalid.c
Fixed by rebase to krb5 1.13.1 (see bug #1203889 - "RFE: Rebase krb5 in RHEL7.2 to krb5 1.13 (krb1.13.2)", note that the bug first rebased to krb5 1.13.1, and then was reopened to to a minor revision rebase to krb5 1.13.2) - formally "resolved" as part of krb5-1.13.2-1.el7 ... ... marking bug as MODIFIED.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHSA-2015-2154.html