MIT Kerberos 5 Key Distribution Center Remote Single Byte Heap Overflow Vulnerability
BID:14236
Info
MIT Kerberos 5 Key Distribution Center Remote Single Byte Heap Overflow Vulnerability
| Bugtraq ID: | 14236 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-1175 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Jun 02 2006 05:22PM |
| Credit: | Discovery is credited to Daniel Wachdorf. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Home Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 Sun Solaris 9_x86 Update 2 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10.0_x86 Sun Solaris 10 Sun SEAM 1.0.2 Sun SEAM 1.0.1 Sun SEAM 1.0 SGI ProPack 3.0 SP6 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 MIT Kerberos 5 5.0 -1.4.1 MIT Kerberos 5 5.0 -1.4 MIT Kerberos 5 5.0 -1.3.6 MIT Kerberos 5 5.0 -1.3.5 MIT Kerberos 5 5.0 -1.3.4 MIT Kerberos 5 5.0 -1.3.3 MIT Kerberos 5 5.0 -1.2beta2 MIT Kerberos 5 5.0 -1.2beta1 MIT Kerberos 5 5.0 -1.1.1 MIT Kerberos 5 5.0 -1.1 MIT Kerberos 5 5.0 -1.0.x Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 IBM DCE 3.2 for AIX Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Apple Mac OS X Server 10.4.2 Apple Mac OS X 10.4.2 |
| Not Vulnerable: | |
Discussion
MIT Kerberos 5 Key Distribution Center Remote Single Byte Heap Overflow Vulnerability
The Kerberos 5 Key Distribution Center (KDC) implementation of the protocol is affected by a remote single-byte heap-overflow vulnerability.
A remote unauthenticated attacker can exploit this vulnerability by sending malformed data through a request over TCP or UDP to an affected computer. This may result in memory corruption and lead to an overflow condition.
If arbitrary code execution occurs, the attacker may gain complete access to an entire Kerberos realm.
All MIT Kerberos 5 releases up to and including krb5-1.4.1 are vulnerable. Third-party application servers employing Kerberos 5 may be affected as well.
The Kerberos 5 Key Distribution Center (KDC) implementation of the protocol is affected by a remote single-byte heap-overflow vulnerability.
A remote unauthenticated attacker can exploit this vulnerability by sending malformed data through a request over TCP or UDP to an affected computer. This may result in memory corruption and lead to an overflow condition.
If arbitrary code execution occurs, the attacker may gain complete access to an entire Kerberos realm.
All MIT Kerberos 5 releases up to and including krb5-1.4.1 are vulnerable. Third-party application servers employing Kerberos 5 may be affected as well.
Exploit / POC
MIT Kerberos 5 Key Distribution Center Remote Single Byte Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
MIT Kerberos 5 Key Distribution Center Remote Single Byte Heap Overflow Vulnerability
Solution:
The vendor has released an advisory (MITKRB5-SA-2005-002) along with a patch for Kerberos 5.0-1.4.1 to resolve this and other issues. This patch may be applied to prior releases as well.
Please see the referenced advisories for further information.
Sun Solaris 8_sparc
Sun Solaris 10
Sun Solaris 10.0_x86
Sun Solaris 9
Sun Solaris 9_x86
Sun Solaris 8_x86
Apple Mac OS X 10.4.2
MIT Kerberos 5 5.0 -1.4.1
Solution:
The vendor has released an advisory (MITKRB5-SA-2005-002) along with a patch for Kerberos 5.0-1.4.1 to resolve this and other issues. This patch may be applied to prior releases as well.
Please see the referenced advisories for further information.
Sun Solaris 8_sparc
Sun Solaris 10
Sun Solaris 10.0_x86
Sun Solaris 9
Sun Solaris 9_x86
Sun Solaris 8_x86
Apple Mac OS X 10.4.2
-
Apple SecUpd2005-007Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=07794&plat form=osx&method=sa/SecUpd2005-007Ti.dmg
MIT Kerberos 5 5.0 -1.4.1
-
MIT 2005-002-patch_1.4.1.txt.asc
http://web.mit.edu/kerberos/advisories/2005-002-patch_1.4.1.txt.asc -
RedHat krb5-debuginfo-1.4.1-5.i386.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-debuginfo-1.4.1-5.ppc.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-debuginfo-1.4.1-5.x86_64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-devel-1.4.1-5.i386.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-devel-1.4.1-5.ppc.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-devel-1.4.1-5.x86_64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-libs-1.4.1-5.i386.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-libs-1.4.1-5.ppc.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-libs-1.4.1-5.ppc64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-libs-1.4.1-5.x86_64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-server-1.4.1-5.i386.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-server-1.4.1-5.ppc.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-server-1.4.1-5.x86_64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-workstation-1.4.1-5.i386.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-workstation-1.4.1-5.ppc.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-workstation-1.4.1-5.x86_64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
References
MIT Kerberos 5 Key Distribution Center Remote Single Byte Heap Overflow Vulnerability
References:
References:
- CLSA-2005:993 - Fix for security vulnerabilities in Kerberos 5 (Conectiva)
- IY85474: MIT KERBEROS VULNERABILITY NO # MITKRB5-SA-2005-002 (IBM)
- Kerberos Homepage (MIT)
- MIT krb5 Security Advisory 2005-002 (MIT)
- RHSA-2005:562-15 - krb5 security update (RedHat)
- RHSA-2005:567-08 - krb5 security update (RedHat)
- Sun Alert ID: 101809 (Sun)
- VU#885830 - MIT Kerberos 5 allows unauthenticated attacker to cause MIT krb5 Key (US-CERT)
- MITKRB5-SA-2005-002: buffer overflow, heap corruption in KDC (Tom Yu
)