MIT Kerberos 5 KRB5_Recvauth Remote Pre-Authentication Double-Free Vulnerability
BID:14239
Info
MIT Kerberos 5 KRB5_Recvauth Remote Pre-Authentication Double-Free Vulnerability
| Bugtraq ID: | 14239 |
| Class: | Design Error |
| CVE: |
CVE-2005-1689 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Sep 26 2006 03:51PM |
| Credit: | Discovery of this issue is credited to Magnus Hagander. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Home Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 Sun Solaris 9_x86 Update 2 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10.0_x86 Sun Solaris 10 Sun SEAM 1.0 SGI ProPack 3.0 SP6 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 MIT Kerberos 5 5.0 -1.4.1 MIT Kerberos 5 5.0 -1.4 MIT Kerberos 5 5.0 -1.3.6 MIT Kerberos 5 5.0 -1.3.5 MIT Kerberos 5 5.0 -1.3.4 MIT Kerberos 5 5.0 -1.3.3 MIT Kerberos 5 5.0 -1.2beta2 MIT Kerberos 5 5.0 -1.2beta1 MIT Kerberos 5 5.0 -1.1.1 MIT Kerberos 5 5.0 -1.1 MIT Kerberos 5 5.0 -1.0.x Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.00 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Apple Mac OS X Server 10.4.2 Apple Mac OS X 10.4.2 |
| Not Vulnerable: | |
Discussion
MIT Kerberos 5 KRB5_Recvauth Remote Pre-Authentication Double-Free Vulnerability
MIT Kerberos 5 is prone to a remote double-free vulnerability. Remote attackers can trigger this issue prior to any authentication whatsoever. The issue exists in the 'revcauth_common()' helper function.
Because of the code path taken in the vulnerable function, exploitation may be hindered. However, attackers may presumably leverage this issue to execute arbitrary code in the context of the affected service.
Note that successful exploitation of this issue on a Kerberos Key Distribution Center (KDC) computer may result in the compromise of an entire Kerberos realm.
MIT Kerberos 5 is prone to a remote double-free vulnerability. Remote attackers can trigger this issue prior to any authentication whatsoever. The issue exists in the 'revcauth_common()' helper function.
Because of the code path taken in the vulnerable function, exploitation may be hindered. However, attackers may presumably leverage this issue to execute arbitrary code in the context of the affected service.
Note that successful exploitation of this issue on a Kerberos Key Distribution Center (KDC) computer may result in the compromise of an entire Kerberos realm.
Exploit / POC
MIT Kerberos 5 KRB5_Recvauth Remote Pre-Authentication Double-Free Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
MIT Kerberos 5 KRB5_Recvauth Remote Pre-Authentication Double-Free Vulnerability
Solution:
The vendor has released patches to address this issue.
Please see the referenced advisories for more information.
Sun Solaris 8_sparc
Sun Solaris 10
Sun Solaris 10.0_x86
Sun Solaris 9
Sun Solaris 9_x86
Sun Solaris 8_x86
Apple Mac OS X 10.4.2
MIT Kerberos 5 5.0 -1.4.1
Solution:
The vendor has released patches to address this issue.
Please see the referenced advisories for more information.
Sun Solaris 8_sparc
-
Sun 112237-13
http://sunsolve.sun.com/search/document.do?assetkey=1-21-112237-13-1 -
Sun 112390-11
http://sunsolve.sun.com/search/document.do?assetkey=1-21-112390-11-1
Sun Solaris 10
Sun Solaris 10.0_x86
Sun Solaris 9
Sun Solaris 9_x86
Sun Solaris 8_x86
-
Sun 112240-10
http://sunsolve.sun.com/search/document.do?assetkey=1-21-112240-10-1 -
Sun 112238-12
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -112238-12-1
Apple Mac OS X 10.4.2
-
Apple SecUpd2005-007Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=07794&plat form=osx&method=sa/SecUpd2005-007Ti.dmg
MIT Kerberos 5 5.0 -1.4.1
-
MIT 2005-003-patch_1.4.1.txt
PGP Sig:http://web.mit.edu/kerberos/advisories/2005-003-patch_1.4.1.txt.asc
http://web.mit.edu/kerberos/advisories/2005-003-patch_1.4.1.txt -
RedHat krb5-debuginfo-1.4.1-5.i386.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-debuginfo-1.4.1-5.ppc.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-debuginfo-1.4.1-5.x86_64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-devel-1.4.1-5.i386.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-devel-1.4.1-5.ppc.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-devel-1.4.1-5.x86_64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-libs-1.4.1-5.i386.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-libs-1.4.1-5.ppc.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-libs-1.4.1-5.ppc64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-libs-1.4.1-5.x86_64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-server-1.4.1-5.i386.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-server-1.4.1-5.ppc.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-server-1.4.1-5.x86_64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-workstation-1.4.1-5.i386.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-workstation-1.4.1-5.ppc.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat krb5-workstation-1.4.1-5.x86_64.rpm
RedHat Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
References
MIT Kerberos 5 KRB5_Recvauth Remote Pre-Authentication Double-Free Vulnerability
References:
References:
- CLSA-2005:993 - Fix for security vulnerabilities in Kerberos 5 (Conectiva)
- Kerberos Homepage (MIT)
- MITKRB5-SA-2005-003 - double-free in krb5_recvauth (MIT)
- RHSA-2005:562-15 - krb5 security update (RedHat)
- Sun Alert ID: 101810 (Sun)
- VU#623332 - MIT Kerberos 5 contains double free vulnerability in "krb5_recvauth( (US-CERT)
- MITKRB5-SA-2005-003: double-free in krb5_recvauth (Tom Yu
)