Skip to navigation

Security Advisory Critical: krb5 security update

Advisory: RHSA-2007:0384-4
Type: Security Advisory
Severity: Critical
Issued on: 2007-06-26
Last updated on: 2007-06-26
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
CVEs (cve.mitre.org): CVE-2007-2442
CVE-2007-2443
CVE-2007-2798

Details

Updated krb5 packages that fix several security flaws are now available for
Red Hat Enterprise Linux 2.1 and 3.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC. kadmind is the KADM5 administration
server.

David Coffey discovered an uninitialized pointer free flaw in the RPC
library used by kadmind. A remote unauthenticated attacker who can access
kadmind could trigger this flaw and cause kadmind to crash or potentially
execute arbitrary code as root. (CVE-2007-2442)

David Coffey also discovered an overflow flaw in the RPC library used by
kadmind. On Red Hat Enterprise Linux, exploitation of this flaw is limited
to a denial of service. A remote unauthenticated attacker who can access
kadmind could trigger this flaw and cause kadmind to crash. (CVE-2007-2443)

A stack buffer overflow flaw was found in kadmind. An authenticated
attacker who can access kadmind could trigger this flaw and potentially
execute arbitrary code on the Kerberos server. (CVE-2007-2798)

For Red Hat Enterprise Linux 2.1, several portability bugs which would lead
to unexpected crashes on the ia64 platform have also been fixed.

Users of krb5-server are advised to update to these erratum packages which
contain backported fixes to correct these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
krb5-1.2.7-66.src.rpm
File outdated by:  RHSA-2010:0423
    MD5: 3c8baf93bf7295fa4d54ddfe70a1d64c
 
IA-32:
krb5-devel-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 4539662077e2665841719421577fabf0
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-server-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 0e3c37a98128874c57ba3abbadc38b84
krb5-workstation-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 4ebc7d0ce73b684e41e77faf24eaba01
 
x86_64:
krb5-devel-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 1c70754189ca4fbd1a37c60d6b8a5ac4
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-libs-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: a9f69c0d1c72d7292d0aa99275120b65
krb5-server-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 3808cda78fdeae3cb6315dbdad962703
krb5-workstation-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 0fc7048dbb02e0d49d8a3b46fcb7c9a6
 
Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
krb5-1.2.2-47.src.rpm
File outdated by:  RHSA-2009:0410
    MD5: c0a472af62885afe44869b685187b346
 
IA-32:
krb5-devel-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 125ca9d18f3020e3f4f9fbb2f9f826bb
krb5-libs-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: d579acc559fc428f2ae971acb848ef7d
krb5-server-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 76d8f32be9bf0686034940f56c5be90d
krb5-workstation-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 44dbf354346c59c318097f867aea368a
 
IA-64:
krb5-devel-1.2.2-47.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: 2a4c48bdf2cb8dac81f671dfde23e755
krb5-libs-1.2.2-47.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: 0ab61f4ec73d0d61b074a1d7cae707d5
krb5-server-1.2.2-47.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: 08c6d5c92fd584d3560b748254804eb5
krb5-workstation-1.2.2-47.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: 3849e726f6124a0b7f80945456ddcca5
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
krb5-1.2.7-66.src.rpm
File outdated by:  RHSA-2010:0423
    MD5: 3c8baf93bf7295fa4d54ddfe70a1d64c
 
IA-32:
krb5-devel-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 4539662077e2665841719421577fabf0
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-server-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 0e3c37a98128874c57ba3abbadc38b84
krb5-workstation-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 4ebc7d0ce73b684e41e77faf24eaba01
 
IA-64:
krb5-devel-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 529e3dfe9091f87d2650a6344c53166b
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-libs-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: b62a442ee20acbabaab8ead16fdedd3b
krb5-server-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 788c56657cb17d70ba6bc8234fc7fec9
krb5-workstation-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: e19f3d0be15fc78f7bad73fff5d85bb6
 
PPC:
krb5-devel-1.2.7-66.ppc.rpm
File outdated by:  RHSA-2010:0423
    MD5: e2101aaee531d1172bbd8b711fa991f3
krb5-libs-1.2.7-66.ppc.rpm
File outdated by:  RHSA-2010:0423
    MD5: 5377f429ed05bffd2b33e7ad194d608b
krb5-libs-1.2.7-66.ppc64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 36af2aba242b084e1e97c9d922fb07e8
krb5-server-1.2.7-66.ppc.rpm
File outdated by:  RHSA-2010:0423
    MD5: fdd47ad4d343841edc410ff09c956891
krb5-workstation-1.2.7-66.ppc.rpm
File outdated by:  RHSA-2010:0423
    MD5: 4ef7b91f106e902fcccf185a5ecb18f7
 
s390:
krb5-devel-1.2.7-66.s390.rpm
File outdated by:  RHSA-2010:0423
    MD5: dbeb7841edded59a0585ae3caf807495
krb5-libs-1.2.7-66.s390.rpm
File outdated by:  RHSA-2010:0423
    MD5: 9a0bb39351602a096dffc95007de2359
krb5-server-1.2.7-66.s390.rpm
File outdated by:  RHSA-2010:0423
    MD5: 7440dda54fa3a23702ae78725f864aa3
krb5-workstation-1.2.7-66.s390.rpm
File outdated by:  RHSA-2010:0423
    MD5: d1c7fd28d6bbb4dbbe259f0239997f46
 
s390x:
krb5-devel-1.2.7-66.s390x.rpm
File outdated by:  RHSA-2010:0423
    MD5: a16888885ce6231b6e83e86e43882aa0
krb5-libs-1.2.7-66.s390.rpm
File outdated by:  RHSA-2010:0423
    MD5: 9a0bb39351602a096dffc95007de2359
krb5-libs-1.2.7-66.s390x.rpm
File outdated by:  RHSA-2010:0423
    MD5: 8cddf8d55a7475eb60e21d8966010ea4
krb5-server-1.2.7-66.s390x.rpm
File outdated by:  RHSA-2010:0423
    MD5: 09ef57a4b90409b7f2930afed65a57d9
krb5-workstation-1.2.7-66.s390x.rpm
File outdated by:  RHSA-2010:0423
    MD5: 031df9b0b3514aaffeba15844098323e
 
x86_64:
krb5-devel-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 1c70754189ca4fbd1a37c60d6b8a5ac4
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-libs-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: a9f69c0d1c72d7292d0aa99275120b65
krb5-server-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 3808cda78fdeae3cb6315dbdad962703
krb5-workstation-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 0fc7048dbb02e0d49d8a3b46fcb7c9a6
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
krb5-1.2.2-47.src.rpm
File outdated by:  RHSA-2009:0410
    MD5: c0a472af62885afe44869b685187b346
 
IA-32:
krb5-devel-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 125ca9d18f3020e3f4f9fbb2f9f826bb
krb5-libs-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: d579acc559fc428f2ae971acb848ef7d
krb5-server-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 76d8f32be9bf0686034940f56c5be90d
krb5-workstation-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 44dbf354346c59c318097f867aea368a
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
krb5-1.2.7-66.src.rpm
File outdated by:  RHSA-2010:0423
    MD5: 3c8baf93bf7295fa4d54ddfe70a1d64c
 
IA-32:
krb5-devel-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 4539662077e2665841719421577fabf0
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-server-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 0e3c37a98128874c57ba3abbadc38b84
krb5-workstation-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 4ebc7d0ce73b684e41e77faf24eaba01
 
IA-64:
krb5-devel-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 529e3dfe9091f87d2650a6344c53166b
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-libs-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: b62a442ee20acbabaab8ead16fdedd3b
krb5-server-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 788c56657cb17d70ba6bc8234fc7fec9
krb5-workstation-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: e19f3d0be15fc78f7bad73fff5d85bb6
 
x86_64:
krb5-devel-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 1c70754189ca4fbd1a37c60d6b8a5ac4
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-libs-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: a9f69c0d1c72d7292d0aa99275120b65
krb5-server-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 3808cda78fdeae3cb6315dbdad962703
krb5-workstation-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 0fc7048dbb02e0d49d8a3b46fcb7c9a6
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
krb5-1.2.2-47.src.rpm
File outdated by:  RHSA-2009:0410
    MD5: c0a472af62885afe44869b685187b346
 
IA-32:
krb5-devel-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 125ca9d18f3020e3f4f9fbb2f9f826bb
krb5-libs-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: d579acc559fc428f2ae971acb848ef7d
krb5-server-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 76d8f32be9bf0686034940f56c5be90d
krb5-workstation-1.2.2-47.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 44dbf354346c59c318097f867aea368a
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
krb5-1.2.7-66.src.rpm
File outdated by:  RHSA-2010:0423
    MD5: 3c8baf93bf7295fa4d54ddfe70a1d64c
 
IA-32:
krb5-devel-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 4539662077e2665841719421577fabf0
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-server-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 0e3c37a98128874c57ba3abbadc38b84
krb5-workstation-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 4ebc7d0ce73b684e41e77faf24eaba01
 
IA-64:
krb5-devel-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 529e3dfe9091f87d2650a6344c53166b
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-libs-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: b62a442ee20acbabaab8ead16fdedd3b
krb5-server-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 788c56657cb17d70ba6bc8234fc7fec9
krb5-workstation-1.2.7-66.ia64.rpm
File outdated by:  RHSA-2010:0423
    MD5: e19f3d0be15fc78f7bad73fff5d85bb6
 
x86_64:
krb5-devel-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 1c70754189ca4fbd1a37c60d6b8a5ac4
krb5-libs-1.2.7-66.i386.rpm
File outdated by:  RHSA-2010:0423
    MD5: 254ab5c46c2ba7f24f43b34ed9e7d198
krb5-libs-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: a9f69c0d1c72d7292d0aa99275120b65
krb5-server-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 3808cda78fdeae3cb6315dbdad962703
krb5-workstation-1.2.7-66.x86_64.rpm
File outdated by:  RHSA-2010:0423
    MD5: 0fc7048dbb02e0d49d8a3b46fcb7c9a6
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
krb5-1.2.2-47.src.rpm
File outdated by:  RHSA-2009:0410
    MD5: c0a472af62885afe44869b685187b346
 
IA-64:
krb5-devel-1.2.2-47.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: 2a4c48bdf2cb8dac81f671dfde23e755
krb5-libs-1.2.2-47.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: 0ab61f4ec73d0d61b074a1d7cae707d5
krb5-server-1.2.2-47.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: 08c6d5c92fd584d3560b748254804eb5
krb5-workstation-1.2.2-47.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: 3849e726f6124a0b7f80945456ddcca5
 

Bugs fixed (see bugzilla for more information)

241590 - kadmin core dumps on ia64
245547 - CVE-2007-2442 krb5 RPC library unitialized pointer free
245548 - CVE-2007-2443 krb5 RPC library stack overflow
245549 - CVE-2007-2798 krb5 kadmind buffer overflow


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/