USN-916-1: Kerberos vulnerabilities


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) USN-916-1: Kerberos vulnerabilities
# 1  
Old 03-23-2010
USN-916-1: Kerberos vulnerabilities

Referenced CVEs:
CVE-2010-0283, CVE-2010-0628


Description:
=========================================================== Ubuntu Security Notice USN-916-1 March 23, 2010 krb5 vulnerabilities CVE-2010-0283, CVE-2010-0628 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 9.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 9.10: krb5-kdc 1.7dfsg~beta3-1ubuntu0.5 libgssapi-krb5-2 1.7dfsg~beta3-1ubuntu0.5 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Emmanuel Bouillon discovered that Kerberos did not correctly handle certain message types. An unauthenticated remote attacker could send specially crafted traffic to cause the KDC to crash, leading to a denial of service. (CVE-2010-0283) Nalin Dahyabhai, Jan iankko Lieskovsky, and Zbysek Mraz discovered that Kerberos did not correctly handle certain GSS packets. An unauthenticated remote attacker could send specially crafted traffic that would cause services using GSS-API to crash, leading to a denial of service. (CVE-2010-0628)





More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question