Security Advisory Updated kerberos packages available

Advisory: RHSA-2002:242-06
Type: Security Advisory
Severity: N/A
Issued on: 2002-11-07
Last updated on: 2002-11-06
Affected Products: Red Hat Linux 6.2
Red Hat Linux 7.0
Red Hat Linux 7.1
Red Hat Linux 7.2
Red Hat Linux 7.3
Red Hat Linux 8.0
OVAL: N/A
CVEs (cve.mitre.org): CVE-2002-1235

Details

A remotely exploitable stack buffer overflow has been found in the Kerberos
v4 compatibility administration daemon distributed with the Red Hat Linux
krb5 packages.

Kerberos is a network authentication system.

A stack buffer overflow has been found in the implementation of the
Kerberos v4 compatibility administration daemon (kadmind4), which is part
of the the MIT krb5 distribution. This vulnerability is present in version
1.2.6 and earlier of the MIT krb5 distribution and can be exploited to gain
unauthorized root access to a KDC host. The attacker does not need to
authenticate to the daemon to successfully perform this attack.

kadmind4 is included in the Kerberos packages in Red Hat Linux 6.2, 7, 7.1,
7.2, 7.3, and 8.0, but by default is not enabled or used.

All users of Kerberos are advised to upgrade to these errata packages which
contain a backported patch and are not vulnerable to this issue.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 6.2

SRPMS:
krb5-1.1.1-30.src.rpm
File outdated by:  RHSA-2003:051
    29835dc36d43458e2896d32fcc6aaefc
 
Alpha:
ftp://updates.redhat.com/6.2/en/os/alpha/krb5-configs-1.1.1-30.alpha.rpm
Missing file
    a03f069ca6c9b9cf40d4dae5238fea8f
ftp://updates.redhat.com/6.2/en/os/alpha/krb5-devel-1.1.1-30.alpha.rpm
Missing file
    093d8de8a7a5ff3cd5150f6209f8d33b
ftp://updates.redhat.com/6.2/en/os/alpha/krb5-libs-1.1.1-30.alpha.rpm
Missing file
    2cf89842ac13c56343faf7c3ce702f93
ftp://updates.redhat.com/6.2/en/os/alpha/krb5-server-1.1.1-30.alpha.rpm
Missing file
    a339c1a19906c541ff5c0ad421fed9ee
ftp://updates.redhat.com/6.2/en/os/alpha/krb5-workstation-1.1.1-30.alpha.rpm
Missing file
    195781d7b6b3097a6fc4b6002b053d6a
 
IA-32:
krb5-configs-1.1.1-30.i386.rpm
File outdated by:  RHSA-2003:051
    098c6a60ba6509669d27c2fd7bdf6e09
krb5-devel-1.1.1-30.i386.rpm
File outdated by:  RHSA-2003:051
    974a35ba5f3d987782e89d3b11c53a0e
krb5-libs-1.1.1-30.i386.rpm
File outdated by:  RHSA-2003:051
    878234d08a4a360636b8d1097f66a608
krb5-server-1.1.1-30.i386.rpm
File outdated by:  RHSA-2003:051
    deaa2561f5a43e4c84c90991f5b6661a
krb5-workstation-1.1.1-30.i386.rpm
File outdated by:  RHSA-2003:051
    d14d28cd6b99d784958199a0a324ac40
 
Sparc:
ftp://updates.redhat.com/6.2/en/os/sparc/krb5-configs-1.1.1-30.sparc.rpm
Missing file
    a8121efd45a11f4989d62ecfaecc785c
ftp://updates.redhat.com/6.2/en/os/sparc/krb5-devel-1.1.1-30.sparc.rpm
Missing file
    fbd89ccc029ea8f0734c8ff16a8a4070
ftp://updates.redhat.com/6.2/en/os/sparc/krb5-libs-1.1.1-30.sparc.rpm
Missing file
    752d0aba417d373af3ca238ac6aceec9
ftp://updates.redhat.com/6.2/en/os/sparc/krb5-server-1.1.1-30.sparc.rpm
Missing file
    01bb57e5c29ff56ce05d97a6a63032d0
ftp://updates.redhat.com/6.2/en/os/sparc/krb5-workstation-1.1.1-30.sparc.rpm
Missing file
    5a1dd1014348d79e9419b217da397f9f
 
Red Hat Linux 7.0

SRPMS:
krb5-1.2.2-15.src.rpm
File outdated by:  RHSA-2003:051
    bd9dfbd903a20985589a1ecb7bf85a55
 
Alpha:
ftp://updates.redhat.com/7.0/en/os/alpha/krb5-devel-1.2.2-15.alpha.rpm
Missing file
    4634252b38d5cc0ac793576f418488d7
ftp://updates.redhat.com/7.0/en/os/alpha/krb5-libs-1.2.2-15.alpha.rpm
Missing file
    58d712af3b4bbc9dc8d18c95071f25e2
ftp://updates.redhat.com/7.0/en/os/alpha/krb5-server-1.2.2-15.alpha.rpm
Missing file
    7dcf3f329b91df414383889ee8861d68
ftp://updates.redhat.com/7.0/en/os/alpha/krb5-workstation-1.2.2-15.alpha.rpm
Missing file
    a873196deacca249259faba88ee3dea0
 
IA-32:
krb5-devel-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    66e5f07a6159b3581cbc4ac4afed705d
krb5-libs-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    48e39df2e734c3915b61a33e7881561d
krb5-server-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    023156f85301778b85f12eeb043ad9d1
krb5-workstation-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    95b863c88b71383fe78f5d286b311209
 
Red Hat Linux 7.1

SRPMS:
krb5-1.2.2-15.src.rpm
File outdated by:  RHSA-2003:051
    bd9dfbd903a20985589a1ecb7bf85a55
 
Alpha:
ftp://updates.redhat.com/7.1/en/os/alpha/krb5-devel-1.2.2-15.alpha.rpm
Missing file
    4634252b38d5cc0ac793576f418488d7
ftp://updates.redhat.com/7.1/en/os/alpha/krb5-libs-1.2.2-15.alpha.rpm
Missing file
    58d712af3b4bbc9dc8d18c95071f25e2
ftp://updates.redhat.com/7.1/en/os/alpha/krb5-server-1.2.2-15.alpha.rpm
Missing file
    7dcf3f329b91df414383889ee8861d68
ftp://updates.redhat.com/7.1/en/os/alpha/krb5-workstation-1.2.2-15.alpha.rpm
Missing file
    a873196deacca249259faba88ee3dea0
 
IA-32:
krb5-devel-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    66e5f07a6159b3581cbc4ac4afed705d
krb5-libs-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    48e39df2e734c3915b61a33e7881561d
krb5-server-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    023156f85301778b85f12eeb043ad9d1
krb5-workstation-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    95b863c88b71383fe78f5d286b311209
 
IA-64:
ftp://updates.redhat.com/7.1/en/os/ia64/krb5-devel-1.2.2-15.ia64.rpm
Missing file
    990af79a788a677108e6084b784a0822
ftp://updates.redhat.com/7.1/en/os/ia64/krb5-libs-1.2.2-15.ia64.rpm
Missing file
    8cd2e5c9ee33713e200153d5786c0f11
ftp://updates.redhat.com/7.1/en/os/ia64/krb5-server-1.2.2-15.ia64.rpm
Missing file
    214314fac18e357f871cb36ee2d4d1c7
ftp://updates.redhat.com/7.1/en/os/ia64/krb5-workstation-1.2.2-15.ia64.rpm
Missing file
    1793ab94f8cc2a8913cef009be761291
 
Red Hat Linux 7.2

SRPMS:
krb5-1.2.2-15.src.rpm
File outdated by:  RHSA-2003:051
    bd9dfbd903a20985589a1ecb7bf85a55
 
IA-32:
krb5-devel-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    66e5f07a6159b3581cbc4ac4afed705d
krb5-libs-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    48e39df2e734c3915b61a33e7881561d
krb5-server-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    023156f85301778b85f12eeb043ad9d1
krb5-workstation-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    95b863c88b71383fe78f5d286b311209
 
IA-64:
krb5-devel-1.2.2-15.ia64.rpm
File outdated by:  RHSA-2003:051
    990af79a788a677108e6084b784a0822
krb5-libs-1.2.2-15.ia64.rpm
File outdated by:  RHSA-2003:051
    8cd2e5c9ee33713e200153d5786c0f11
krb5-server-1.2.2-15.ia64.rpm
File outdated by:  RHSA-2003:051
    214314fac18e357f871cb36ee2d4d1c7
krb5-workstation-1.2.2-15.ia64.rpm
File outdated by:  RHSA-2003:051
    1793ab94f8cc2a8913cef009be761291
 
Red Hat Linux 7.3

SRPMS:
krb5-1.2.4-3.src.rpm
File outdated by:  RHSA-2003:051
    798f28aa820a9be1521e2a4554c5ea44
 
IA-32:
krb5-devel-1.2.4-3.i386.rpm
File outdated by:  RHSA-2003:051
    bbdada43207b16dea1f1f70d1605f47c
krb5-libs-1.2.4-3.i386.rpm
File outdated by:  RHSA-2003:051
    ef2c48903f9f39d32af13f42bcc05b32
krb5-server-1.2.4-3.i386.rpm
File outdated by:  RHSA-2003:051
    a79d2cf51f59cc6b7e1b321dcdb7f303
krb5-workstation-1.2.4-3.i386.rpm
File outdated by:  RHSA-2003:051
    6acfd6a13c27b03a6412438b60981d17
 
Red Hat Linux 8.0

SRPMS:
krb5-1.2.5-7.src.rpm
File outdated by:  RHSA-2003:051
    24fb18f8ed3de853a4d1a5661516b77a
 
IA-32:
krb5-devel-1.2.5-7.i386.rpm
File outdated by:  RHSA-2003:051
    f7135174d00471fb33ff41a93f5c8242
krb5-libs-1.2.5-7.i386.rpm
File outdated by:  RHSA-2003:051
    4eb103a0ffe97d45ec0ddb5977cc208f
krb5-server-1.2.5-7.i386.rpm
File outdated by:  RHSA-2003:051
    0f9cbbd3381defa181793b28d503884f
krb5-workstation-1.2.5-7.i386.rpm
File outdated by:  RHSA-2003:051
    ed8e5d8c8d323d4e85f2a6beef54caf8
 

References


Keywords

kadmind4, krb5


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/