Skip to navigation

Security Advisory Updated kerberos packages available

Advisory: RHSA-2002:242-06
Type: Security Advisory
Severity: N/A
Issued on: 2002-11-07
Last updated on: 2002-11-06
Affected Products: Red Hat Linux 6.2
Red Hat Linux 7.0
Red Hat Linux 7.1
Red Hat Linux 7.2
Red Hat Linux 7.3
Red Hat Linux 8.0
CVEs (cve.mitre.org): CVE-2002-1235

Details

A remotely exploitable stack buffer overflow has been found in the Kerberos
v4 compatibility administration daemon distributed with the Red Hat Linux
krb5 packages.

Kerberos is a network authentication system.

A stack buffer overflow has been found in the implementation of the
Kerberos v4 compatibility administration daemon (kadmind4), which is part
of the the MIT krb5 distribution. This vulnerability is present in version
1.2.6 and earlier of the MIT krb5 distribution and can be exploited to gain
unauthorized root access to a KDC host. The attacker does not need to
authenticate to the daemon to successfully perform this attack.

kadmind4 is included in the Kerberos packages in Red Hat Linux 6.2, 7, 7.1,
7.2, 7.3, and 8.0, but by default is not enabled or used.

All users of Kerberos are advised to upgrade to these errata packages which
contain a backported patch and are not vulnerable to this issue.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 6.2

SRPMS:
krb5-1.1.1-30.src.rpm
File outdated by:  RHSA-2003:051
    MD5: 29835dc36d43458e2896d32fcc6aaefc
 
Alpha:
ftp://updates.redhat.com/rhn/repository/NULL/krb5-configs/1.1.1-30/alpha/krb5-configs-1.1.1-30.alpha.rpm
Missing file
    MD5: a03f069ca6c9b9cf40d4dae5238fea8f
ftp://updates.redhat.com/rhn/repository/NULL/krb5-devel/1.1.1-30/alpha/krb5-devel-1.1.1-30.alpha.rpm
Missing file
    MD5: 093d8de8a7a5ff3cd5150f6209f8d33b
ftp://updates.redhat.com/rhn/repository/NULL/krb5-libs/1.1.1-30/alpha/krb5-libs-1.1.1-30.alpha.rpm
Missing file
    MD5: 2cf89842ac13c56343faf7c3ce702f93
ftp://updates.redhat.com/rhn/repository/NULL/krb5-server/1.1.1-30/alpha/krb5-server-1.1.1-30.alpha.rpm
Missing file
    MD5: a339c1a19906c541ff5c0ad421fed9ee
ftp://updates.redhat.com/rhn/repository/NULL/krb5-workstation/1.1.1-30/alpha/krb5-workstation-1.1.1-30.alpha.rpm
Missing file
    MD5: 195781d7b6b3097a6fc4b6002b053d6a
 
IA-32:
krb5-configs-1.1.1-30.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 098c6a60ba6509669d27c2fd7bdf6e09
krb5-devel-1.1.1-30.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 974a35ba5f3d987782e89d3b11c53a0e
krb5-libs-1.1.1-30.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 878234d08a4a360636b8d1097f66a608
krb5-server-1.1.1-30.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: deaa2561f5a43e4c84c90991f5b6661a
krb5-workstation-1.1.1-30.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: d14d28cd6b99d784958199a0a324ac40
 
Sparc:
ftp://updates.redhat.com/rhn/repository/NULL/krb5-configs/1.1.1-30/sparc/krb5-configs-1.1.1-30.sparc.rpm
Missing file
    MD5: a8121efd45a11f4989d62ecfaecc785c
ftp://updates.redhat.com/rhn/repository/NULL/krb5-devel/1.1.1-30/sparc/krb5-devel-1.1.1-30.sparc.rpm
Missing file
    MD5: fbd89ccc029ea8f0734c8ff16a8a4070
ftp://updates.redhat.com/rhn/repository/NULL/krb5-libs/1.1.1-30/sparc/krb5-libs-1.1.1-30.sparc.rpm
Missing file
    MD5: 752d0aba417d373af3ca238ac6aceec9
ftp://updates.redhat.com/rhn/repository/NULL/krb5-server/1.1.1-30/sparc/krb5-server-1.1.1-30.sparc.rpm
Missing file
    MD5: 01bb57e5c29ff56ce05d97a6a63032d0
ftp://updates.redhat.com/rhn/repository/NULL/krb5-workstation/1.1.1-30/sparc/krb5-workstation-1.1.1-30.sparc.rpm
Missing file
    MD5: 5a1dd1014348d79e9419b217da397f9f
 
Red Hat Linux 7.0

SRPMS:
krb5-1.2.2-15.src.rpm
File outdated by:  RHSA-2003:051
    MD5: bd9dfbd903a20985589a1ecb7bf85a55
 
Alpha:
ftp://updates.redhat.com/rhn/repository/NULL/krb5-devel/1.2.2-15/alpha/krb5-devel-1.2.2-15.alpha.rpm
Missing file
    MD5: 4634252b38d5cc0ac793576f418488d7
ftp://updates.redhat.com/rhn/repository/NULL/krb5-libs/1.2.2-15/alpha/krb5-libs-1.2.2-15.alpha.rpm
Missing file
    MD5: 58d712af3b4bbc9dc8d18c95071f25e2
ftp://updates.redhat.com/rhn/repository/NULL/krb5-server/1.2.2-15/alpha/krb5-server-1.2.2-15.alpha.rpm
Missing file
    MD5: 7dcf3f329b91df414383889ee8861d68
ftp://updates.redhat.com/rhn/repository/NULL/krb5-workstation/1.2.2-15/alpha/krb5-workstation-1.2.2-15.alpha.rpm
Missing file
    MD5: a873196deacca249259faba88ee3dea0
 
IA-32:
krb5-devel-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 66e5f07a6159b3581cbc4ac4afed705d
krb5-libs-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 48e39df2e734c3915b61a33e7881561d
krb5-server-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 023156f85301778b85f12eeb043ad9d1
krb5-workstation-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 95b863c88b71383fe78f5d286b311209
 
Red Hat Linux 7.1

SRPMS:
krb5-1.2.2-15.src.rpm
File outdated by:  RHSA-2003:051
    MD5: bd9dfbd903a20985589a1ecb7bf85a55
 
Alpha:
ftp://updates.redhat.com/rhn/repository/NULL/krb5-devel/1.2.2-15/alpha/krb5-devel-1.2.2-15.alpha.rpm
Missing file
    MD5: 4634252b38d5cc0ac793576f418488d7
ftp://updates.redhat.com/rhn/repository/NULL/krb5-libs/1.2.2-15/alpha/krb5-libs-1.2.2-15.alpha.rpm
Missing file
    MD5: 58d712af3b4bbc9dc8d18c95071f25e2
ftp://updates.redhat.com/rhn/repository/NULL/krb5-server/1.2.2-15/alpha/krb5-server-1.2.2-15.alpha.rpm
Missing file
    MD5: 7dcf3f329b91df414383889ee8861d68
ftp://updates.redhat.com/rhn/repository/NULL/krb5-workstation/1.2.2-15/alpha/krb5-workstation-1.2.2-15.alpha.rpm
Missing file
    MD5: a873196deacca249259faba88ee3dea0
 
IA-32:
krb5-devel-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 66e5f07a6159b3581cbc4ac4afed705d
krb5-libs-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 48e39df2e734c3915b61a33e7881561d
krb5-server-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 023156f85301778b85f12eeb043ad9d1
krb5-workstation-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 95b863c88b71383fe78f5d286b311209
 
IA-64:
ftp://updates.redhat.com/rhn/repository/NULL/krb5-devel/1.2.2-15/ia64/krb5-devel-1.2.2-15.ia64.rpm
Missing file
    MD5: 990af79a788a677108e6084b784a0822
ftp://updates.redhat.com/rhn/repository/NULL/krb5-libs/1.2.2-15/ia64/krb5-libs-1.2.2-15.ia64.rpm
Missing file
    MD5: 8cd2e5c9ee33713e200153d5786c0f11
ftp://updates.redhat.com/rhn/repository/NULL/krb5-server/1.2.2-15/ia64/krb5-server-1.2.2-15.ia64.rpm
Missing file
    MD5: 214314fac18e357f871cb36ee2d4d1c7
ftp://updates.redhat.com/rhn/repository/NULL/krb5-workstation/1.2.2-15/ia64/krb5-workstation-1.2.2-15.ia64.rpm
Missing file
    MD5: 1793ab94f8cc2a8913cef009be761291
 
Red Hat Linux 7.2

SRPMS:
krb5-1.2.2-15.src.rpm
File outdated by:  RHSA-2003:051
    MD5: bd9dfbd903a20985589a1ecb7bf85a55
 
IA-32:
krb5-devel-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 66e5f07a6159b3581cbc4ac4afed705d
krb5-libs-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 48e39df2e734c3915b61a33e7881561d
krb5-server-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 023156f85301778b85f12eeb043ad9d1
krb5-workstation-1.2.2-15.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 95b863c88b71383fe78f5d286b311209
 
IA-64:
krb5-devel-1.2.2-15.ia64.rpm
File outdated by:  RHSA-2003:051
    MD5: 990af79a788a677108e6084b784a0822
krb5-libs-1.2.2-15.ia64.rpm
File outdated by:  RHSA-2003:051
    MD5: 8cd2e5c9ee33713e200153d5786c0f11
krb5-server-1.2.2-15.ia64.rpm
File outdated by:  RHSA-2003:051
    MD5: 214314fac18e357f871cb36ee2d4d1c7
krb5-workstation-1.2.2-15.ia64.rpm
File outdated by:  RHSA-2003:051
    MD5: 1793ab94f8cc2a8913cef009be761291
 
Red Hat Linux 7.3

SRPMS:
krb5-1.2.4-3.src.rpm
File outdated by:  RHSA-2003:051
    MD5: 798f28aa820a9be1521e2a4554c5ea44
 
IA-32:
krb5-devel-1.2.4-3.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: bbdada43207b16dea1f1f70d1605f47c
krb5-libs-1.2.4-3.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: ef2c48903f9f39d32af13f42bcc05b32
krb5-server-1.2.4-3.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: a79d2cf51f59cc6b7e1b321dcdb7f303
krb5-workstation-1.2.4-3.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 6acfd6a13c27b03a6412438b60981d17
 
Red Hat Linux 8.0

SRPMS:
krb5-1.2.5-7.src.rpm
File outdated by:  RHSA-2003:051
    MD5: 24fb18f8ed3de853a4d1a5661516b77a
 
IA-32:
krb5-devel-1.2.5-7.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: f7135174d00471fb33ff41a93f5c8242
krb5-libs-1.2.5-7.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 4eb103a0ffe97d45ec0ddb5977cc208f
krb5-server-1.2.5-7.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: 0f9cbbd3381defa181793b28d503884f
krb5-workstation-1.2.5-7.i386.rpm
File outdated by:  RHSA-2003:051
    MD5: ed8e5d8c8d323d4e85f2a6beef54caf8
 

References


Keywords

kadmind4, krb5


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/