Security Advisory Updated Kerberos 5 packages are now available for Red Hat Linux.

Advisory: RHSA-2000:025-13
Type: Security Advisory
Severity: N/A
Issued on: 2000-05-16
Last updated on: 2000-06-16
Affected Products:
OVAL: N/A
CVEs (cve.mitre.org): CVE-2000-0389
CVE-2000-0390
CVE-2000-0391
CVE-2000-0392

Details

Security vulnerabilities have been found in the Kerberos 5 implementation
shipped with Red Hat Linux 6.2.

A number of possible buffer overruns were found in libraries included
in the affected packages. A denial-of-service vulnerability was also found
in the ksu program.

* A remote user may gain unauthorized root access to a machine running
services authenticated with Kerberos 4.

* A remote user may gain unauthorized root access to a machine running
krshd, regardless of whether the program is configured to accept
Kerberos 4 authentication.

* A local user may gain unauthorized root access by exploiting v4rcp
or ksu.

* A remote user can cause a KDC to become unresponsive or crash by sending
it an improperly formatted request.

* A remote user may execute certain FTP commands without authorization
on systems using the FTP server included in the krb5-workstation
package.

* An attacker with access to a local account may gain unauthorized
root access on systems using the FTP server included in the
krb5-workstation package.

The prior errata announcement for these package contained incorrect md5sum
values. The correct md5sums are listed below.


Solution

For each RPM for your particular architecture, run:

rpm -Fvh [filename]

where filename is the name of the RPM.

Updated packages


References


Keywords

N/A


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/