Updated Kerberos packages fix a number of vulnerabilities found in MIT
Kerberos.
Kerberos is a network authentication system. The MIT Kerberos team
released an advisory describing a number of vulnerabilities that affect the
kerberos packages shipped by Red Hat. These vulnerabilities include:
An integer signedness error in the ASN.1 decoder before version 1.2.5
allows remote attackers to cause a denial of service (crash) via a large
unsigned data element length, which is later used as a negative value. The
Common Vulnerabilities and Exposures project has assigned the name
CAN-2002-0036 to this issue. Red Hat Linux 8.0 and later are not affected
by this issue.
The Key Distribution Center (KDC) before version 1.2.5 allows remote,
authenticated attackers to cause a denial of service (crash) on KDCs within
the same realm using a certain protocol request that causes a null
dereference (CAN-2003-0058). Red Hat Linux 8.0 and later are not affected
by this issue.
The Key Distribution Center (KDC) allows remote, authenticated attackers to
cause a denial of service (crash) on KDCs within the same realm using a
certain protocol request that causes an out-of-bounds read of an array
(CAN-2003-0072).
The Key Distribution Center (KDC) allows remote, authenticated attackers
to cause a denial of service (crash) on KDCs within the same realm using a
certain protocol request that causes the KDC to corrupt its heap
(CAN-2003-0082).
A vulnerability in Kerberos before version 1.2.3 allows users from one
realm to impersonate users in other realms that have the same inter-realm
keys (CAN-2003-0059). Red Hat Linux 7.3 and later are not affected by this
issue.
The MIT advisory for these issues also mentions format string
vulnerabilities in the logging routines (CAN-2003-0060). Previous versions
of the kerberos packages from Red Hat already contain fixes for this issue.
Vulnerabilities have been found in the support for triple-DES keys in the
implementation of the Kerberos IV authentication protocol which is included
in MIT Kerberos (CAN-2003-0139).
Vulnerabilities have been found in the Kerberos IV authentication protocol
which allow an attacker with knowledge of a cross-realm key, which is
shared with another realm, to impersonate any principal in that realm to
any service in that realm. This vulnerability can only be closed by
disabling cross-realm authentication in Kerberos IV (CAN-2003-0138).
Vulnerabilities have been found in the RPC library used by the kadmin
service in Kerberos 5. A faulty length check in the RPC library exposes
kadmind to an integer overflow which can be used to crash kadmind
(CAN-2003-0028).
All users of Kerberos are advised to upgrade to these errata packages,
which disable cross-realm authentication by default for Kerberos IV and
which contain backported patches that correct these issues.
| Red Hat Linux 6.2 |
|
| SRPMS: |
ftp://updates.redhat.com/6.2/en/os/SRPMS/krb5-1.1.1-40.src.rpm
Missing file |
ab4510357651cc37fc8a838c94a62417 |
| |
| IA-32: |
ftp://updates.redhat.com/6.2/en/os/i386/krb5-configs-1.1.1-40.i386.rpm
Missing file |
7a2cba73bdd878f29592f792a9dfe794 |
ftp://updates.redhat.com/6.2/en/os/i386/krb5-devel-1.1.1-40.i386.rpm
Missing file |
51431cdcc3526f92c2fd9c8f53f76282 |
ftp://updates.redhat.com/6.2/en/os/i386/krb5-libs-1.1.1-40.i386.rpm
Missing file |
c20e1e80232276ea908eac478d46ad80 |
ftp://updates.redhat.com/6.2/en/os/i386/krb5-server-1.1.1-40.i386.rpm
Missing file |
4937fba2e1e8aeba94b503f30f9768e3 |
ftp://updates.redhat.com/6.2/en/os/i386/krb5-workstation-1.1.1-40.i386.rpm
Missing file |
7cc03b89723f626a0ff956c9a579757d |
| |
| Red Hat Linux 7.0 |
|
| SRPMS: |
ftp://updates.redhat.com/7.0/en/os/SRPMS/krb5-1.2.2-24.src.rpm
Missing file |
015332e33f81730516dd76a64f9da81f |
| |
| IA-32: |
ftp://updates.redhat.com/7.0/en/os/i386/krb5-devel-1.2.2-24.i386.rpm
Missing file |
234fa434540d9e0d9f15dd49248efc68 |
ftp://updates.redhat.com/7.0/en/os/i386/krb5-libs-1.2.2-24.i386.rpm
Missing file |
b54a47e387a5a6ea7158dc5ac0111893 |
ftp://updates.redhat.com/7.0/en/os/i386/krb5-server-1.2.2-24.i386.rpm
Missing file |
4b366d5cfb1f6ee9f5580643e5ac3d67 |
ftp://updates.redhat.com/7.0/en/os/i386/krb5-workstation-1.2.2-24.i386.rpm
Missing file |
2b0951733ae63682644b1b10cfad2135 |
| |
| Red Hat Linux 7.1 |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/SRPMS/krb5-1.2.2-24.src.rpm
Missing file |
015332e33f81730516dd76a64f9da81f |
| |
| IA-32: |
ftp://updates.redhat.com/7.1/en/os/i386/krb5-devel-1.2.2-24.i386.rpm
Missing file |
234fa434540d9e0d9f15dd49248efc68 |
ftp://updates.redhat.com/7.1/en/os/i386/krb5-libs-1.2.2-24.i386.rpm
Missing file |
b54a47e387a5a6ea7158dc5ac0111893 |
ftp://updates.redhat.com/7.1/en/os/i386/krb5-server-1.2.2-24.i386.rpm
Missing file |
4b366d5cfb1f6ee9f5580643e5ac3d67 |
ftp://updates.redhat.com/7.1/en/os/i386/krb5-workstation-1.2.2-24.i386.rpm
Missing file |
2b0951733ae63682644b1b10cfad2135 |
| |
| Red Hat Linux 7.2 |
|
| SRPMS: |
ftp://updates.redhat.com/7.2/en/os/SRPMS/krb5-1.2.2-24.src.rpm
Missing file |
015332e33f81730516dd76a64f9da81f |
| |
| IA-32: |
ftp://updates.redhat.com/7.2/en/os/i386/krb5-devel-1.2.2-24.i386.rpm
Missing file |
234fa434540d9e0d9f15dd49248efc68 |
ftp://updates.redhat.com/7.2/en/os/i386/krb5-libs-1.2.2-24.i386.rpm
Missing file |
b54a47e387a5a6ea7158dc5ac0111893 |
ftp://updates.redhat.com/7.2/en/os/i386/krb5-server-1.2.2-24.i386.rpm
Missing file |
4b366d5cfb1f6ee9f5580643e5ac3d67 |
ftp://updates.redhat.com/7.2/en/os/i386/krb5-workstation-1.2.2-24.i386.rpm
Missing file |
2b0951733ae63682644b1b10cfad2135 |
| |
| IA-64: |
ftp://updates.redhat.com/7.2/en/os/ia64/krb5-devel-1.2.2-24.ia64.rpm
Missing file |
dde89228aae54a6960568f0345cd0f4b |
ftp://updates.redhat.com/7.2/en/os/ia64/krb5-libs-1.2.2-24.ia64.rpm
Missing file |
b5bde7b8ec06f663263a269a0f67eb32 |
ftp://updates.redhat.com/7.2/en/os/ia64/krb5-server-1.2.2-24.ia64.rpm
Missing file |
241fbf250c32c1323da057e364916f7b |
ftp://updates.redhat.com/7.2/en/os/ia64/krb5-workstation-1.2.2-24.ia64.rpm
Missing file |
91670b5b3df3b2d10a1cbd4bc1f82514 |
| |
| Red Hat Linux 7.3 |
|
| SRPMS: |
ftp://updates.redhat.com/7.3/en/os/SRPMS/krb5-1.2.4-11.src.rpm
Missing file |
88bff9c228e1c57bc5e9b938043ea36e |
| |
| IA-32: |
ftp://updates.redhat.com/7.3/en/os/i386/krb5-devel-1.2.4-11.i386.rpm
Missing file |
58dfab84469ba94f2f0730b6c73c0b63 |
ftp://updates.redhat.com/7.3/en/os/i386/krb5-libs-1.2.4-11.i386.rpm
Missing file |
aecb7ec8b6854d3b4db2030629b3e757 |
ftp://updates.redhat.com/7.3/en/os/i386/krb5-server-1.2.4-11.i386.rpm
Missing file |
259f54ef7c8edcfb3668c81ba66c54e2 |
ftp://updates.redhat.com/7.3/en/os/i386/krb5-workstation-1.2.4-11.i386.rpm
Missing file |
2f6f7bc14778d933e3c016b417eee575 |
| |
| Red Hat Linux 8.0 |
|
| SRPMS: |
ftp://updates.redhat.com/8.0/en/os/SRPMS/krb5-1.2.5-15.src.rpm
Missing file |
7c578680da8bc516b76031b140e04235 |
| |
| IA-32: |
ftp://updates.redhat.com/8.0/en/os/i386/krb5-devel-1.2.5-15.i386.rpm
Missing file |
9e0d547d33efc56c93932e92a8560aa0 |
ftp://updates.redhat.com/8.0/en/os/i386/krb5-libs-1.2.5-15.i386.rpm
Missing file |
9e36f2192f29e5e4c162cf1af0ee4f79 |
ftp://updates.redhat.com/8.0/en/os/i386/krb5-server-1.2.5-15.i386.rpm
Missing file |
addeb716fb5ca29f0d403d586d4746b3 |
ftp://updates.redhat.com/8.0/en/os/i386/krb5-workstation-1.2.5-15.i386.rpm
Missing file |
c3431c68451484ebe77645b552a49408 |
| |