Security Advisory krb5 security update

Advisory: RHSA-2003:052-25
Type: Security Advisory
Severity: Critical
Issued on: 2003-03-27
Last updated on: 2003-03-27
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2002-0036
CVE-2003-0028
CVE-2003-0058
CVE-2003-0059
CVE-2003-0072
CVE-2003-0082
CVE-2003-0138
CVE-2003-0139
CVE-2004-0772

Details

Updated kerberos packages fix a number of vulnerabilities found in MIT
Kerberos.

Kerberos is a network authentication system. The MIT Kerberos team
released an advisory describing a number of vulnerabilities that affect the
kerberos packages shipped by Red Hat.

An integer signedness error in the ASN.1 decoder before version 1.2.5
allows remote attackers to cause a denial of service via a large unsigned
data element length, which is later used as a negative value. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2002-0036
to this issue.

The Key Distribution Center (KDC) before version 1.2.5 allows remote,
authenticated, attackers to cause a denial of service (crash) on KDCs
within the same realm via a certain protocol request that:

- causes a null pointer dereference (CAN-2003-0058).

- causes the KDC to corrupt its heap (CAN-2003-0082).

A vulnerability in Kerberos before version 1.2.3 allows users from
one realm to impersonate users in other realms that have the same
inter-realm keys (CAN-2003-0059).

The MIT advisory for these issues also mentions format string
vulnerabilities in the logging routines (CAN-2003-0060). Previous versions
of the kerberos packages from Red Hat already contain fixes for this issue.

Vulnerabilities have been found in the implementation of support for
triple-DES keys in the implementation of the Kerberos IV authentication
protocol included in MIT Kerberos (CAN-2003-0139).

Vulnerabilities have been found in the Kerberos IV authentication protocol
which allow an attacker with knowledge of a cross-realm key that is shared
with another realm to impersonate any principal in that realm to any
service in that realm. This vulnerability can only be closed by disabling
cross-realm authentication in Kerberos IV (CAN-2003-0138).

Vulnerabilities have been found in the RPC library used by the kadmin
service in Kerberos 5. A faulty length check in the RPC library exposes
kadmind to an integer overflow which can be used to crash kadmind
(CAN-2003-0028).

All users of Kerberos are advised to upgrade to these errata packages,
which disable cross-realm authentication by default for Kerberos IV and
which contain backported patches to correct these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

Please note that this update is available via Red Hat Network. To use Red
Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
krb5-1.2.2-24.src.rpm
File outdated by:  RHSA-2008:0181
    015332e33f81730516dd76a64f9da81f
 
IA-32:
krb5-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    234fa434540d9e0d9f15dd49248efc68
krb5-libs-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    b54a47e387a5a6ea7158dc5ac0111893
krb5-server-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    4b366d5cfb1f6ee9f5580643e5ac3d67
krb5-workstation-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    2b0951733ae63682644b1b10cfad2135
 
IA-64:
krb5-devel-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2008:0181
    dde89228aae54a6960568f0345cd0f4b
krb5-libs-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2008:0181
    b5bde7b8ec06f663263a269a0f67eb32
krb5-server-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2008:0181
    241fbf250c32c1323da057e364916f7b
krb5-workstation-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2008:0181
    91670b5b3df3b2d10a1cbd4bc1f82514
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
krb5-1.2.2-24.src.rpm
File outdated by:  RHSA-2008:0181
    015332e33f81730516dd76a64f9da81f
 
IA-32:
krb5-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    234fa434540d9e0d9f15dd49248efc68
krb5-libs-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    b54a47e387a5a6ea7158dc5ac0111893
krb5-server-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    4b366d5cfb1f6ee9f5580643e5ac3d67
krb5-workstation-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    2b0951733ae63682644b1b10cfad2135
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
krb5-1.2.2-24.src.rpm
File outdated by:  RHSA-2008:0181
    015332e33f81730516dd76a64f9da81f
 
IA-32:
krb5-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    234fa434540d9e0d9f15dd49248efc68
krb5-libs-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    b54a47e387a5a6ea7158dc5ac0111893
krb5-server-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    4b366d5cfb1f6ee9f5580643e5ac3d67
krb5-workstation-1.2.2-24.i386.rpm
File outdated by:  RHSA-2008:0181
    2b0951733ae63682644b1b10cfad2135
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
krb5-1.2.2-24.src.rpm
File outdated by:  RHSA-2008:0181
    015332e33f81730516dd76a64f9da81f
 
IA-64:
krb5-devel-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2008:0181
    dde89228aae54a6960568f0345cd0f4b
krb5-libs-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2008:0181
    b5bde7b8ec06f663263a269a0f67eb32
krb5-server-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2008:0181
    241fbf250c32c1323da057e364916f7b
krb5-workstation-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2008:0181
    91670b5b3df3b2d10a1cbd4bc1f82514
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

83616 - Multiple kerberos vulnerabilities


References


Keywords

kerberos, krb5


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/