Skip to navigation

Security Advisory krb5 security update

Advisory: RHSA-2004:448-12
Type: Security Advisory
Severity: Critical
Issued on: 2004-08-31
Last updated on: 2004-08-31
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
CVEs (cve.mitre.org): CVE-2004-0642
CVE-2004-0643
CVE-2004-0644

Details

Updated Kerberos (krb5) packages that correct double-free and ASN.1
parsing bugs are now available for Red Hat Enterprise Linux.

Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

Several double-free bugs were found in the Kerberos 5 KDC and libraries. A
remote attacker could potentially exploit these flaws to execuate arbitrary
code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0642 and CAN-2004-0643 to these issues.

A double-free bug was also found in the krb524 server (CAN-2004-0772),
however this issue was fixed for Red Hat Enterprise Linux 2.1 users by a
previous erratum, RHSA-2003:052.

An infinite loop bug was found in the Kerberos 5 ASN.1 decoder library. A
remote attacker may be able to trigger this flaw and cause a denial of
service. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0644 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

IA-32:
krb5-devel-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: f5fc294848750e1186efd792aaca3fa1
krb5-libs-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 1da2499c2aa50026be1eda1774cb8fc0
krb5-server-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 72749007a7033ff2a31dc4ee20a439c7
krb5-workstation-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: be44496d6d25c3e5c1754ce871b3de49
 
IA-64:
krb5-devel-1.2.2-31.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: d81f70e064675a486c9a796fd1ea6297
krb5-libs-1.2.2-31.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: bd5eeae1a8d4b97585bbe67b746edb1d
krb5-server-1.2.2-31.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: bb30a6820d6c475452458a3cebca55b8
krb5-workstation-1.2.2-31.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: c7b3177d7e82f890ef669196c2ff0f8f
 
Red Hat Enterprise Linux ES (v. 2.1)

IA-32:
krb5-devel-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: f5fc294848750e1186efd792aaca3fa1
krb5-libs-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 1da2499c2aa50026be1eda1774cb8fc0
krb5-server-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 72749007a7033ff2a31dc4ee20a439c7
krb5-workstation-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: be44496d6d25c3e5c1754ce871b3de49
 
Red Hat Enterprise Linux WS (v. 2.1)

IA-32:
krb5-devel-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: f5fc294848750e1186efd792aaca3fa1
krb5-libs-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 1da2499c2aa50026be1eda1774cb8fc0
krb5-server-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: 72749007a7033ff2a31dc4ee20a439c7
krb5-workstation-1.2.2-31.i386.rpm
File outdated by:  RHSA-2009:0410
    MD5: be44496d6d25c3e5c1754ce871b3de49
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

IA-64:
krb5-devel-1.2.2-31.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: d81f70e064675a486c9a796fd1ea6297
krb5-libs-1.2.2-31.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: bd5eeae1a8d4b97585bbe67b746edb1d
krb5-server-1.2.2-31.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: bb30a6820d6c475452458a3cebca55b8
krb5-workstation-1.2.2-31.ia64.rpm
File outdated by:  RHSA-2009:0410
    MD5: c7b3177d7e82f890ef669196c2ff0f8f
 

Bugs fixed (see bugzilla for more information)

129680 - Upgrading to krb5-libs 1.2.2-27 can cause undefined symbol __dn_expand


References


Keywords

asn.1, double-free, krb5


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/