Jump to content

Advisories MDKSA-2007:077-1: Updated krb5 packages fix vulnerabilities


paul
 Share

Recommended Posts

A vulnerability was found in the username handling of the MIT krb5

telnet daemon. A remote attacker that could access the telnet port

of a target machine could login as root without requiring a password

(CVE-2007-0956).

 

Buffer overflows in the kadmin server daemon were discovered that could

be exploited by a remote attacker able to access the KDC. Successful

exploitation could allow for the execution of arbitrary code with

the privileges of the KDC or kadmin server processes (CVE-2007-0957).

 

Finally, a double-free flaw was discovered in the GSSAPI library used

by the kadmin server daemon, which could lead to a denial of service

condition or the execution of arbitrary code with the privileges of

the KDC or kadmin server processes (CVE-2007-1216).

 

Updated packages have been patched to address this issue.

 

Update:

 

Packages for Mandriva Linux 2007.1 are now available.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...