]> git.ipfire.org Git - thirdparty/krb5.git/commitdiff
Update for krb5-1.21.3 krb5-1.21.3-final
authorGreg Hudson <ghudson@mit.edu>
Wed, 26 Jun 2024 17:19:09 +0000 (13:19 -0400)
committerGreg Hudson <ghudson@mit.edu>
Wed, 26 Jun 2024 17:19:09 +0000 (13:19 -0400)
29 files changed:
README
src/man/k5identity.man
src/man/k5login.man
src/man/k5srvutil.man
src/man/kadm5.acl.man
src/man/kadmin.man
src/man/kadmind.man
src/man/kdb5_ldap_util.man
src/man/kdb5_util.man
src/man/kdc.conf.man
src/man/kdestroy.man
src/man/kerberos.man
src/man/kinit.man
src/man/klist.man
src/man/kpasswd.man
src/man/kprop.man
src/man/kpropd.man
src/man/kproplog.man
src/man/krb5-config.man
src/man/krb5.conf.man
src/man/krb5kdc.man
src/man/ksu.man
src/man/kswitch.man
src/man/ktutil.man
src/man/kvno.man
src/man/sclient.man
src/man/sserver.man
src/patchlevel.h
src/po/mit-krb5.pot

diff --git a/README b/README
index 2202c29e29289da4c75917d4885c38b3f1405831..6d6f7f16e3dad4e70768e7cd1eaa0e01d26bc48b 100644 (file)
--- a/README
+++ b/README
@@ -97,6 +97,30 @@ removed.
 Beginning with the krb5-1.18 release, all support for single-DES
 encryption types has been removed.
 
+Major changes in 1.21.3 (2024-06-26)
+------------------------------------
+
+This is a bug fix release.
+
+* Fix vulnerabilities in GSS message token handling [CVE-2024-37370,
+  CVE-2024-37371].
+
+* Fix a potential bad pointer free in krb5_cccol_have_contents().
+
+* Fix a memory leak in the macOS ccache type.
+
+krb5-1.21.2 changes by ticket ID
+--------------------------------
+
+9102    Eliminate sim_client include of getopt.h
+9103    segfault trying to free a garbage pointer
+9104    Work around Doxygen 1.9.7 change
+9107    In PKINIT, check for null PKCS7 enveloped fields
+9109    memory leak on macos
+9115    Fix leak in KDC NDR encoding
+9125    Formatting error in realm_config.rst
+9128    Fix vulnerabilities in GSS message token handling
+
 Major changes in 1.21.2 (2023-08-14)
 ------------------------------------
 
@@ -324,6 +348,7 @@ reports, suggestions, and valuable resources:
     Michael Calmer
     Andrea Campi
     Julien Chaffraix
+    Jacob Champion
     Puran Chand
     Ravi Channavajhala
     Srinivas Cheruku
@@ -454,6 +479,7 @@ reports, suggestions, and valuable resources:
     Mantas Mikulėnas
     Markus Moeller
     Kyle Moffett
+    Jon Moore
     Paul Moore
     Keiichi Mori
     Michael Morony
@@ -506,6 +532,7 @@ reports, suggestions, and valuable resources:
     Richard Silverman
     Cel Skeggs
     Simo Sorce
+    Anthony Sottile
     Michael Spang
     Michael Ströder
     Bjørn Tore Sund
index 352514d6d35c4bc44a6ada5440ae69b84d936234..917644599f0ced6940f496df58cf6978031f0415 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "K5IDENTITY" "5" " " "1.21.2" "MIT Kerberos"
+.TH "K5IDENTITY" "5" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 k5identity \- Kerberos V5 client principal selection rules
 .SH DESCRIPTION
index d530a46ccdb13bc36fed284e91bd0ee14c347698..6605a7ee4427eb7835549cc1e421e5847c0279be 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "K5LOGIN" "5" " " "1.21.2" "MIT Kerberos"
+.TH "K5LOGIN" "5" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 k5login \- Kerberos V5 acl file for host access
 .SH DESCRIPTION
index 16299fa42d6bef9d7d0a3e97c5defa06b948c9a8..f3590b6ef542882470d21c305287dd66da0a2957 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "K5SRVUTIL" "1" " " "1.21.2" "MIT Kerberos"
+.TH "K5SRVUTIL" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 k5srvutil \- host key table (keytab) manipulation utility
 .SH SYNOPSIS
index e2fe1bb19403a1212f76f98732e9be1c00b052d0..334db0cac55afc0888c651dc62c93f0fff6f4916 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KADM5.ACL" "5" " " "1.21.2" "MIT Kerberos"
+.TH "KADM5.ACL" "5" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kadm5.acl \- Kerberos ACL file
 .SH DESCRIPTION
index 3dbd8a372bedb6ad83d8d4d4662d70a1aec235d4..8413e70ccd60ffc1a40b1c9a1a8b213d255c226f 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KADMIN" "1" " " "1.21.2" "MIT Kerberos"
+.TH "KADMIN" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kadmin \- Kerberos V5 database administration program
 .SH SYNOPSIS
index 3d56d5257ffbc98364f1337ac749147e681b0714..32b9213a7c83b09782406cd00624da48974bda71 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KADMIND" "8" " " "1.21.2" "MIT Kerberos"
+.TH "KADMIND" "8" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kadmind \- KADM5 administration server
 .SH SYNOPSIS
index 68eea0238f7ca386bf87eac5d1962495362628b1..125e59ab26530b9af54c9025fdc822bed497bb47 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KDB5_LDAP_UTIL" "8" " " "1.21.2" "MIT Kerberos"
+.TH "KDB5_LDAP_UTIL" "8" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kdb5_ldap_util \- Kerberos configuration utility
 .SH SYNOPSIS
index 1271a452a5f203930859afce2f2dde5223da4da7..d43d913d09c8b9123bf19108d9551f37697123c8 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KDB5_UTIL" "8" " " "1.21.2" "MIT Kerberos"
+.TH "KDB5_UTIL" "8" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kdb5_util \- Kerberos database maintenance utility
 .SH SYNOPSIS
index 6be49e6c2ed2bf72f89be377d6dd2ed9a76f104f..98a722238c9ed5acd6d30232f41c644cf8ea8346 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KDC.CONF" "5" " " "1.21.2" "MIT Kerberos"
+.TH "KDC.CONF" "5" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kdc.conf \- Kerberos V5 KDC configuration file
 .sp
index 6ae2a686172aa5e778a301398b9302fee7a203e0..c17b254ef9e4d4f18963316059a31e00cb9bb84e 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KDESTROY" "1" " " "1.21.2" "MIT Kerberos"
+.TH "KDESTROY" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kdestroy \- destroy Kerberos tickets
 .SH SYNOPSIS
index 85d4e8020d1b742dfb51feb8b321429e39ca9da3..ec1d84dd27fa7460efaa77c3a0549993c150fa99 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KERBEROS" "7" " " "1.21.2" "MIT Kerberos"
+.TH "KERBEROS" "7" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kerberos \- Overview of using Kerberos
 .SH DESCRIPTION
index 9dffc81c95047827615f839c10eac4031ed41ea1..32f57c420924e004f8a5607c8ecf2e4ebfd7f9d5 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KINIT" "1" " " "1.21.2" "MIT Kerberos"
+.TH "KINIT" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kinit \- obtain and cache Kerberos ticket-granting ticket
 .SH SYNOPSIS
index 91cfb3cd4d56f981545d27d12bda792a96500b28..3061e5ccde83418c61f58b942fa11fda027f9e9c 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KLIST" "1" " " "1.21.2" "MIT Kerberos"
+.TH "KLIST" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 klist \- list cached Kerberos tickets
 .SH SYNOPSIS
index c79eb96cf69aff911561c83233c883bb296d74ca..846224b684ddfc955aa382e527b93ea02e0d06fc 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KPASSWD" "1" " " "1.21.2" "MIT Kerberos"
+.TH "KPASSWD" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kpasswd \- change a user's Kerberos password
 .SH SYNOPSIS
index c4037c415035a70b0e13cfbf0b93f018ce2a72c2..609117390c3d89bdc4cb307b36a8e832ca66c3a7 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KPROP" "8" " " "1.21.2" "MIT Kerberos"
+.TH "KPROP" "8" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kprop \- propagate a Kerberos V5 principal database to a replica server
 .SH SYNOPSIS
index 37cb073918b0896ea268f8ae66e259825654ec32..2c44d4fb468f68d079b5166abddf334072c1c096 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KPROPD" "8" " " "1.21.2" "MIT Kerberos"
+.TH "KPROPD" "8" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kpropd \- Kerberos V5 replica KDC update server
 .SH SYNOPSIS
index d15851ffed40bceeff00d03b11bf64782dc05467..f7e93f351f26f72f8b82d81e93bf5747b88b56a4 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KPROPLOG" "8" " " "1.21.2" "MIT Kerberos"
+.TH "KPROPLOG" "8" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kproplog \- display the contents of the Kerberos principal update log
 .SH SYNOPSIS
index c417b368c811604bb5f8635bdb2d26a5035a19c1..021c581181ed3c4a456dd9640541312d6a62bc15 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KRB5-CONFIG" "1" " " "1.21.2" "MIT Kerberos"
+.TH "KRB5-CONFIG" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 krb5-config \- tool for linking against MIT Kerberos libraries
 .SH SYNOPSIS
index afa86a096ed6d92dd93f8dce2b7a733ff0882f87..6c0e9aff8c401c49d5b97abbe606231f0a0e7e6c 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KRB5.CONF" "5" " " "1.21.2" "MIT Kerberos"
+.TH "KRB5.CONF" "5" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 krb5.conf \- Kerberos configuration file
 .sp
index c71cc182c567071179d4d16d474d701766a31dae..dc6bc4dacee8b6ceddbb98629c1319a369c66e7c 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KRB5KDC" "8" " " "1.21.2" "MIT Kerberos"
+.TH "KRB5KDC" "8" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 krb5kdc \- Kerberos V5 KDC
 .SH SYNOPSIS
index 1f7b3d0eec5f78b417f50de22f8411097c7a5135..bb87113103f50a9fd1ab63b34d7b8f6bb07b1e93 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KSU" "1" " " "1.21.2" "MIT Kerberos"
+.TH "KSU" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 ksu \- Kerberized super-user
 .SH SYNOPSIS
index ce729fcb00e697f4945921a3f1fbfbafeafe3cf2..83ae58fcb29c6a91c9f0a5f6506e5357d6b85705 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KSWITCH" "1" " " "1.21.2" "MIT Kerberos"
+.TH "KSWITCH" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kswitch \- switch primary ticket cache
 .SH SYNOPSIS
index bae4d6bdf8f46592805855132d78ab508155f885..63466cf14f3d5203a2554db63e3a0187d872a5c5 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KTUTIL" "1" " " "1.21.2" "MIT Kerberos"
+.TH "KTUTIL" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 ktutil \- Kerberos keytab file maintenance utility
 .SH SYNOPSIS
index 397d15a6a43b328f97766c22ae4a352fda7db186..9b5cd3919b400f02b32545a0e4d40575e7cfbb6e 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "KVNO" "1" " " "1.21.2" "MIT Kerberos"
+.TH "KVNO" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 kvno \- print key version numbers of Kerberos principals
 .SH SYNOPSIS
index 5335a5d1f9db5028f1e64458985c6ce1bb1d8b51..0ccd1947057118142cdc5e34c176139f5b3a6aba 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "SCLIENT" "1" " " "1.21.2" "MIT Kerberos"
+.TH "SCLIENT" "1" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 sclient \- sample Kerberos version 5 client
 .SH SYNOPSIS
index e3876a90aba7befe47bb1cea2191b3298c875c61..59de1631c0bb284e2363d0af14d6135e0c8a429d 100644 (file)
@@ -27,7 +27,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .\" new: \\n[rst2man-indent\\n[rst2man-indent-level]]
 .in \\n[rst2man-indent\\n[rst2man-indent-level]]u
 ..
-.TH "SSERVER" "8" " " "1.21.2" "MIT Kerberos"
+.TH "SSERVER" "8" " " "1.21.3" "MIT Kerberos"
 .SH NAME
 sserver \- sample Kerberos version 5 server
 .SH SYNOPSIS
index fbbbe376985788cb6d1db9cd5ce8438123a9527b..903ebf910bb3259407367b76b6b80076518db73f 100644 (file)
@@ -51,7 +51,7 @@
  */
 #define KRB5_MAJOR_RELEASE 1
 #define KRB5_MINOR_RELEASE 21
-#define KRB5_PATCHLEVEL 2
-#define KRB5_RELTAIL "postrelease"
+#define KRB5_PATCHLEVEL 3
+/* #undef KRB5_RELTAIL */
 /* #undef KRB5_RELDATE */
-#define KRB5_RELTAG "krb5-1.21"
+#define KRB5_RELTAG "krb5-1.21.3-final"
index 75e9fdb21007687196064f6e5c53ca0af50a7a39..52a3fb78e261ac6250b2cbc6ce221a757fa3a1fe 100644 (file)
@@ -6,9 +6,9 @@
 #, fuzzy
 msgid ""
 msgstr ""
-"Project-Id-Version: mit-krb5 1.21.2-postrelease\n"
+"Project-Id-Version: mit-krb5 1.21.3\n"
 "Report-Msgid-Bugs-To: \n"
-"POT-Creation-Date: 2024-06-26 12:58-0400\n"
+"POT-Creation-Date: 2024-06-26 13:09-0400\n"
 "PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n"
 "Last-Translator: FULL NAME <EMAIL@ADDRESS>\n"
 "Language-Team: LANGUAGE <LL@li.org>\n"