remctl 3.14 released

2018-04-01 Thread Russ Allbery
Version 3.14 of remctl has been released. This is a minimal security fix over 3.13 (with some additional warning fixes for the latest version of GCC). remctl is a client/server application that supports remote execution of specific commands, using Kerberos GSS-API for authentication. Authorizatio

remctl 2018-04-01 Security Advisory

2018-04-01 Thread Russ Allbery
Vulnerability type: Use after free, double free Versions affected: 3.12 and 3.13 Versions fixed: 3.14 and later Reported:2018-03-30 Public announcement: 2018-04-01 CVE IDs: CVE-2018-0493 Santosh Ananthakrishnan discovered incorrect memory management in the remctld a