Bug Fix Advisory krb5 bug fix update

Advisory: RHBA-2009:0997-1
Type: Bug Fix Advisory
Severity: N/A
Issued on: 2009-05-18
Last updated on: 2009-05-18
Affected Products: Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 4)
OVAL: N/A

Details

Updated krb5 packages that resolve several issues are now available.

Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through the use of symmetric
encryption and a trusted third party: the Key Distribution Center (KDC).

These updated krb5 packages provide fixes for the following bugs:

* a user with an expired password who logged in to the system using the
Kerberos-aware telnet protocol was correctly prompted to change their
password. However, it was then possible for that user to change their
password to a new but insecure password such as "aaa". With this update,
the Pluggable Authentication Modules (PAM) system enforces quality checks
on passwords which are changed over the Kerberos-aware telnet protocol,
thus solving this potential problem.

* attempting to log in to a remote host using the rlogin command failed
when the user's password was expired. With this update, users are able to
log in successfully to the system with rlogin and change their expired
password.

* when copying data to a full NFS directory, rcp failed silently and did
not report an error, which led to silent data loss. With this update, rcp
does report an error under this condition.

* PAM modules use PAM_RHOST, PAM_USER and PAM_SERVICE, among other items,
as factors when making access control decisions. However, certain Kerberos
utilities did not correctly set the item which PAM modules read when
determining from which host a remote connection was being attempted. This
has been corrected in this update so that the necessary Kerberos utilities
set PAM items correctly and appropriately, which is needed for a
PAM-enabled Kerberos 5.

All users of krb5 are advised to upgrade to these updated packages, which
resolve these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

Red Hat Desktop (v. 4)

SRPMS:
krb5-1.3.4-62.el4.src.rpm     802ac4712f32cc0c17d3274eb11868eb
 
IA-32:
krb5-devel-1.3.4-62.el4.i386.rpm     b6237ed929e6579134950795e59b1234
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-server-1.3.4-62.el4.i386.rpm     58c8531eae4258996e5e772c65a95fda
krb5-workstation-1.3.4-62.el4.i386.rpm     a79a0e57299df26d7f27987a56eecedb
 
x86_64:
krb5-devel-1.3.4-62.el4.x86_64.rpm     320016f728309d840dee909e66acf9eb
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-libs-1.3.4-62.el4.x86_64.rpm     4a33cee5bd3a052e273d45d4c62efddd
krb5-server-1.3.4-62.el4.x86_64.rpm     104f77879d371dd45ea30c6ecd51f64b
krb5-workstation-1.3.4-62.el4.x86_64.rpm     fe4fc50cdfd8d9c5cfefb5df384c1fb9
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
krb5-1.3.4-62.el4.src.rpm     802ac4712f32cc0c17d3274eb11868eb
 
IA-32:
krb5-devel-1.3.4-62.el4.i386.rpm     b6237ed929e6579134950795e59b1234
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-server-1.3.4-62.el4.i386.rpm     58c8531eae4258996e5e772c65a95fda
krb5-workstation-1.3.4-62.el4.i386.rpm     a79a0e57299df26d7f27987a56eecedb
 
IA-64:
krb5-devel-1.3.4-62.el4.ia64.rpm     50c537826018f93e46f36e71c22ad1fb
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-libs-1.3.4-62.el4.ia64.rpm     bb117d1df3d4d06bc40698cb2c1f5bc5
krb5-server-1.3.4-62.el4.ia64.rpm     2935759ce3242820fe26165155d937c1
krb5-workstation-1.3.4-62.el4.ia64.rpm     ea459ac178b5c1b4a375af43f799b48b
 
PPC:
krb5-devel-1.3.4-62.el4.ppc.rpm     538bf53a919dae94745fef8744f930be
krb5-libs-1.3.4-62.el4.ppc.rpm     8f26c6e85f1fb8038b2d713d9b135153
krb5-libs-1.3.4-62.el4.ppc64.rpm     52308d7cdba698642cc0b51f9b5d37e6
krb5-server-1.3.4-62.el4.ppc.rpm     e7f2dc33e7f5ff79954147c5097aaab8
krb5-workstation-1.3.4-62.el4.ppc.rpm     aa814e50ff3e41367fd57a2f2f751efb
 
s390:
krb5-devel-1.3.4-62.el4.s390.rpm     51ccf5b9480615dcd1fd293a9e993cb1
krb5-libs-1.3.4-62.el4.s390.rpm     4305c8897a56ae61a471684c2eeb6246
krb5-server-1.3.4-62.el4.s390.rpm     8cf5ef885684d59b60827856dfe71641
krb5-workstation-1.3.4-62.el4.s390.rpm     081abe0d89632ea3a64bddf5999ef310
 
s390x:
krb5-devel-1.3.4-62.el4.s390x.rpm     174b2886866e4db96362e6ebd77e4a18
krb5-libs-1.3.4-62.el4.s390.rpm     4305c8897a56ae61a471684c2eeb6246
krb5-libs-1.3.4-62.el4.s390x.rpm     e143727a52c62da7bc63c42685268cb2
krb5-server-1.3.4-62.el4.s390x.rpm     bf3f50240ebea06745fb88ddab3c537f
krb5-workstation-1.3.4-62.el4.s390x.rpm     125517ac6d0a83bb7798814526f8f6eb
 
x86_64:
krb5-devel-1.3.4-62.el4.x86_64.rpm     320016f728309d840dee909e66acf9eb
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-libs-1.3.4-62.el4.x86_64.rpm     4a33cee5bd3a052e273d45d4c62efddd
krb5-server-1.3.4-62.el4.x86_64.rpm     104f77879d371dd45ea30c6ecd51f64b
krb5-workstation-1.3.4-62.el4.x86_64.rpm     fe4fc50cdfd8d9c5cfefb5df384c1fb9
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
krb5-1.3.4-62.el4.src.rpm     802ac4712f32cc0c17d3274eb11868eb
 
IA-32:
krb5-devel-1.3.4-62.el4.i386.rpm     b6237ed929e6579134950795e59b1234
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-server-1.3.4-62.el4.i386.rpm     58c8531eae4258996e5e772c65a95fda
krb5-workstation-1.3.4-62.el4.i386.rpm     a79a0e57299df26d7f27987a56eecedb
 
IA-64:
krb5-devel-1.3.4-62.el4.ia64.rpm     50c537826018f93e46f36e71c22ad1fb
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-libs-1.3.4-62.el4.ia64.rpm     bb117d1df3d4d06bc40698cb2c1f5bc5
krb5-server-1.3.4-62.el4.ia64.rpm     2935759ce3242820fe26165155d937c1
krb5-workstation-1.3.4-62.el4.ia64.rpm     ea459ac178b5c1b4a375af43f799b48b
 
x86_64:
krb5-devel-1.3.4-62.el4.x86_64.rpm     320016f728309d840dee909e66acf9eb
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-libs-1.3.4-62.el4.x86_64.rpm     4a33cee5bd3a052e273d45d4c62efddd
krb5-server-1.3.4-62.el4.x86_64.rpm     104f77879d371dd45ea30c6ecd51f64b
krb5-workstation-1.3.4-62.el4.x86_64.rpm     fe4fc50cdfd8d9c5cfefb5df384c1fb9
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
krb5-1.3.4-62.el4.src.rpm     802ac4712f32cc0c17d3274eb11868eb
 
IA-32:
krb5-devel-1.3.4-62.el4.i386.rpm     b6237ed929e6579134950795e59b1234
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-server-1.3.4-62.el4.i386.rpm     58c8531eae4258996e5e772c65a95fda
krb5-workstation-1.3.4-62.el4.i386.rpm     a79a0e57299df26d7f27987a56eecedb
 
IA-64:
krb5-devel-1.3.4-62.el4.ia64.rpm     50c537826018f93e46f36e71c22ad1fb
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-libs-1.3.4-62.el4.ia64.rpm     bb117d1df3d4d06bc40698cb2c1f5bc5
krb5-server-1.3.4-62.el4.ia64.rpm     2935759ce3242820fe26165155d937c1
krb5-workstation-1.3.4-62.el4.ia64.rpm     ea459ac178b5c1b4a375af43f799b48b
 
x86_64:
krb5-devel-1.3.4-62.el4.x86_64.rpm     320016f728309d840dee909e66acf9eb
krb5-libs-1.3.4-62.el4.i386.rpm     3840572790afae80f05920281789ee65
krb5-libs-1.3.4-62.el4.x86_64.rpm     4a33cee5bd3a052e273d45d4c62efddd
krb5-server-1.3.4-62.el4.x86_64.rpm     104f77879d371dd45ea30c6ecd51f64b
krb5-workstation-1.3.4-62.el4.x86_64.rpm     fe4fc50cdfd8d9c5cfefb5df384c1fb9
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

461900 - rcp does not return ENOSPC error on full NFS-File system
479082 - user can set insecure password using PAMified telnet
479083 - can not login with rlogin as an user with expired password



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/