MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability
BID:21970
Info
MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability
| Bugtraq ID: | 21970 |
| Class: | Design Error |
| CVE: |
CVE-2006-6143 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2007 12:00AM |
| Updated: | Mar 19 2015 09:42AM |
| Credit: | Andrew Korty is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Operating System Enterprise Server 2.0 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux 9.3 S.u.S.E. Linux 10.1 S.u.S.E. Linux 10.0 rPath rPath Linux 1 OpenPKG OpenPKG Stable OpenPKG OpenPKG E1.0-Solid OpenPKG OpenPKG Current OpenPKG OpenPKG 2-Stable-20061018 MIT Kerberos 5 1.5.1 MIT Kerberos 5 1.5 MIT Kerberos 5 1.4.3 MIT Kerberos 5 1.4.2 MIT Kerberos 5 1.4.1 MIT Kerberos 5 1.4 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Apple Mac OS X Server 10.4.9 Apple Mac OS X 10.4.9 |
| Not Vulnerable: | |
Discussion
MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability
MIT Kerberos 5 is prone to a remote code-execution vulnerability. This issue resides in the server-side portion of the Kerberos RPC library. Currently, the 'kadmind' service is known to be vulnerable, but other applications that use this library may also be affected.
An attacker can exploit this issue to execute arbitrary code with administrative privileges, completely compromising affected computers. Failed exploit attempts will result in a denial of service. After a Kerberos database computer has been compromised, attackers may gain unauthorized access to
other services that rely on the Kerberos infrastructure for authentication.
MIT Kerberos 5 is prone to a remote code-execution vulnerability. This issue resides in the server-side portion of the Kerberos RPC library. Currently, the 'kadmind' service is known to be vulnerable, but other applications that use this library may also be affected.
An attacker can exploit this issue to execute arbitrary code with administrative privileges, completely compromising affected computers. Failed exploit attempts will result in a denial of service. After a Kerberos database computer has been compromised, attackers may gain unauthorized access to
other services that rely on the Kerberos infrastructure for authentication.
Exploit / POC
MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability
Solution:
The vendor has released patches to address this issue. Please see the references for more information.
MIT Kerberos 5 1.4
MIT Kerberos 5 1.4.1
MIT Kerberos 5 1.4.2
MIT Kerberos 5 1.4.3
MIT Kerberos 5 1.5
MIT Kerberos 5 1.5.1
Apple Mac OS X Server 10.4.9
Apple Mac OS X 10.4.9
Solution:
The vendor has released patches to address this issue. Please see the references for more information.
MIT Kerberos 5 1.4
-
MIT 2006-002-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2006-002-patch.txt.asc
MIT Kerberos 5 1.4.1
-
MIT 2006-002-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2006-002-patch.txt.asc
MIT Kerberos 5 1.4.2
-
MIT 2006-002-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2006-002-patch.txt.asc
MIT Kerberos 5 1.4.3
-
MIT 2006-002-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2006-002-patch.txt.asc -
Ubuntu krb5-admin-server_1.4.3-5ubuntu0.2_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-admin-serv er_1.4.3-5ubuntu0.2_amd64.deb -
Ubuntu krb5-admin-server_1.4.3-5ubuntu0.2_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-admin-serv er_1.4.3-5ubuntu0.2_i386.deb -
Ubuntu krb5-admin-server_1.4.3-5ubuntu0.2_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-admin-serv er_1.4.3-5ubuntu0.2_powerpc.deb -
Ubuntu krb5-admin-server_1.4.3-5ubuntu0.2_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-admin-serv er_1.4.3-5ubuntu0.2_sparc.deb -
Ubuntu krb5-admin-server_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-admin-serv er_1.4.3-9ubuntu1.1_amd64.deb -
Ubuntu krb5-admin-server_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-admin-serv er_1.4.3-9ubuntu1.1_i386.deb -
Ubuntu krb5-admin-server_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-admin-serv er_1.4.3-9ubuntu1.1_powerpc.deb -
Ubuntu krb5-admin-server_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-admin-serv er_1.4.3-9ubuntu1.1_sparc.deb -
Ubuntu krb5-clients_1.4.3-5ubuntu0.2_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 4.3-5ubuntu0.2_amd64.deb -
Ubuntu krb5-clients_1.4.3-5ubuntu0.2_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 4.3-5ubuntu0.2_i386.deb -
Ubuntu krb5-clients_1.4.3-5ubuntu0.2_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 4.3-5ubuntu0.2_powerpc.deb -
Ubuntu krb5-clients_1.4.3-5ubuntu0.2_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 4.3-5ubuntu0.2_sparc.deb -
Ubuntu krb5-clients_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 4.3-9ubuntu1.1_amd64.deb -
Ubuntu krb5-clients_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 4.3-9ubuntu1.1_i386.deb -
Ubuntu krb5-clients_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 4.3-9ubuntu1.1_powerpc.deb -
Ubuntu krb5-clients_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 4.3-9ubuntu1.1_sparc.deb -
Ubuntu krb5-doc_1.4.3-5ubuntu0.2_all.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/krb5-doc_1.4.3-5ubu ntu0.2_all.deb -
Ubuntu krb5-doc_1.4.3-9ubuntu1.1_all.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/krb5-doc_1.4.3-9ubu ntu1.1_all.deb -
Ubuntu krb5-ftpd_1.4.3-5ubuntu0.2_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.4.3 -5ubuntu0.2_amd64.deb -
Ubuntu krb5-ftpd_1.4.3-5ubuntu0.2_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.4.3 -5ubuntu0.2_i386.deb -
Ubuntu krb5-ftpd_1.4.3-5ubuntu0.2_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.4.3 -5ubuntu0.2_powerpc.deb -
Ubuntu krb5-ftpd_1.4.3-5ubuntu0.2_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.4.3 -5ubuntu0.2_sparc.deb -
Ubuntu krb5-ftpd_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.4.3 -9ubuntu1.1_amd64.deb -
Ubuntu krb5-ftpd_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.4.3 -9ubuntu1.1_i386.deb -
Ubuntu krb5-ftpd_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.4.3 -9ubuntu1.1_powerpc.deb -
Ubuntu krb5-ftpd_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.4.3 -9ubuntu1.1_sparc.deb -
Ubuntu krb5-kdc_1.4.3-5ubuntu0.2_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.4.3- 5ubuntu0.2_amd64.deb -
Ubuntu krb5-kdc_1.4.3-5ubuntu0.2_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.4.3- 5ubuntu0.2_i386.deb -
Ubuntu krb5-kdc_1.4.3-5ubuntu0.2_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.4.3- 5ubuntu0.2_powerpc.deb -
Ubuntu krb5-kdc_1.4.3-5ubuntu0.2_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.4.3- 5ubuntu0.2_sparc.deb -
Ubuntu krb5-kdc_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.4.3- 9ubuntu1.1_amd64.deb -
Ubuntu krb5-kdc_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.4.3- 9ubuntu1.1_i386.deb -
Ubuntu krb5-kdc_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.4.3- 9ubuntu1.1_powerpc.deb -
Ubuntu krb5-kdc_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.4.3- 9ubuntu1.1_sparc.deb -
Ubuntu krb5-rsh-server_1.4.3-5ubuntu0.2_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.4.3-5ubuntu0.2_amd64.deb -
Ubuntu krb5-rsh-server_1.4.3-5ubuntu0.2_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.4.3-5ubuntu0.2_i386.deb -
Ubuntu krb5-rsh-server_1.4.3-5ubuntu0.2_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.4.3-5ubuntu0.2_powerpc.deb -
Ubuntu krb5-rsh-server_1.4.3-5ubuntu0.2_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.4.3-5ubuntu0.2_sparc.deb -
Ubuntu krb5-rsh-server_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.4.3-9ubuntu1.1_amd64.deb -
Ubuntu krb5-rsh-server_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.4.3-9ubuntu1.1_i386.deb -
Ubuntu krb5-rsh-server_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.4.3-9ubuntu1.1_powerpc.deb -
Ubuntu krb5-rsh-server_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.4.3-9ubuntu1.1_sparc.deb -
Ubuntu krb5-telnetd_1.4.3-5ubuntu0.2_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-telnetd_1. 4.3-5ubuntu0.2_amd64.deb -
Ubuntu krb5-telnetd_1.4.3-5ubuntu0.2_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-telnetd_1. 4.3-5ubuntu0.2_i386.deb -
Ubuntu krb5-telnetd_1.4.3-5ubuntu0.2_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-telnetd_1. 4.3-5ubuntu0.2_powerpc.deb -
Ubuntu krb5-telnetd_1.4.3-5ubuntu0.2_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-telnetd_1. 4.3-5ubuntu0.2_sparc.deb -
Ubuntu krb5-telnetd_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-telnetd_1. 4.3-9ubuntu1.1_amd64.deb -
Ubuntu krb5-telnetd_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-telnetd_1. 4.3-9ubuntu1.1_i386.deb -
Ubuntu krb5-telnetd_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-telnetd_1. 4.3-9ubuntu1.1_powerpc.deb -
Ubuntu krb5-telnetd_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-telnetd_1. 4.3-9ubuntu1.1_sparc.deb -
Ubuntu krb5-user_1.4.3-5ubuntu0.2_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-user_1.4.3 -5ubuntu0.2_amd64.deb -
Ubuntu krb5-user_1.4.3-5ubuntu0.2_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-user_1.4.3 -5ubuntu0.2_i386.deb -
Ubuntu krb5-user_1.4.3-5ubuntu0.2_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-user_1.4.3 -5ubuntu0.2_powerpc.deb -
Ubuntu krb5-user_1.4.3-5ubuntu0.2_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-user_1.4.3 -5ubuntu0.2_sparc.deb -
Ubuntu krb5-user_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-user_1.4.3 -9ubuntu1.1_amd64.deb -
Ubuntu krb5-user_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-user_1.4.3 -9ubuntu1.1_i386.deb -
Ubuntu krb5-user_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-user_1.4.3 -9ubuntu1.1_powerpc.deb -
Ubuntu krb5-user_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-user_1.4.3 -9ubuntu1.1_sparc.deb -
Ubuntu libkadm55_1.4.3-5ubuntu0.2_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkadm55_1.4.3-5ub untu0.2_amd64.deb -
Ubuntu libkadm55_1.4.3-5ubuntu0.2_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkadm55_1.4.3-5ub untu0.2_i386.deb -
Ubuntu libkadm55_1.4.3-5ubuntu0.2_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkadm55_1.4.3-5ub untu0.2_powerpc.deb -
Ubuntu libkadm55_1.4.3-5ubuntu0.2_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkadm55_1.4.3-5ub untu0.2_sparc.deb -
Ubuntu libkadm55_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkadm55_1.4.3-9ub untu1.1_amd64.deb -
Ubuntu libkadm55_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkadm55_1.4.3-9ub untu1.1_i386.deb -
Ubuntu libkadm55_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkadm55_1.4.3-9ub untu1.1_powerpc.deb -
Ubuntu libkadm55_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkadm55_1.4.3-9ub untu1.1_sparc.deb -
Ubuntu libkrb5-dbg_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dbg_1.4.3-9 ubuntu1.1_amd64.deb -
Ubuntu libkrb5-dbg_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dbg_1.4.3-9 ubuntu1.1_i386.deb -
Ubuntu libkrb5-dbg_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dbg_1.4.3-9 ubuntu1.1_powerpc.deb -
Ubuntu libkrb5-dbg_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dbg_1.4.3-9 ubuntu1.1_sparc.deb -
Ubuntu libkrb5-dev_1.4.3-5ubuntu0.2_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dev_1.4.3-5 ubuntu0.2_amd64.deb -
Ubuntu libkrb5-dev_1.4.3-5ubuntu0.2_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dev_1.4.3-5 ubuntu0.2_i386.deb -
Ubuntu libkrb5-dev_1.4.3-5ubuntu0.2_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dev_1.4.3-5 ubuntu0.2_powerpc.deb -
Ubuntu libkrb5-dev_1.4.3-5ubuntu0.2_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dev_1.4.3-5 ubuntu0.2_sparc.deb -
Ubuntu libkrb5-dev_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dev_1.4.3-9 ubuntu1.1_amd64.deb -
Ubuntu libkrb5-dev_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dev_1.4.3-9 ubuntu1.1_i386.deb -
Ubuntu libkrb5-dev_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dev_1.4.3-9 ubuntu1.1_powerpc.deb -
Ubuntu libkrb5-dev_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb5-dev_1.4.3-9 ubuntu1.1_sparc.deb -
Ubuntu libkrb53_1.4.3-5ubuntu0.2_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb53_1.4.3-5ubu ntu0.2_amd64.deb -
Ubuntu libkrb53_1.4.3-5ubuntu0.2_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb53_1.4.3-5ubu ntu0.2_i386.deb -
Ubuntu libkrb53_1.4.3-5ubuntu0.2_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb53_1.4.3-5ubu ntu0.2_powerpc.deb -
Ubuntu libkrb53_1.4.3-5ubuntu0.2_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb53_1.4.3-5ubu ntu0.2_sparc.deb -
Ubuntu libkrb53_1.4.3-9ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb53_1.4.3-9ubu ntu1.1_amd64.deb -
Ubuntu libkrb53_1.4.3-9ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb53_1.4.3-9ubu ntu1.1_i386.deb -
Ubuntu libkrb53_1.4.3-9ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb53_1.4.3-9ubu ntu1.1_powerpc.deb -
Ubuntu libkrb53_1.4.3-9ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/krb5/libkrb53_1.4.3-9ubu ntu1.1_sparc.deb
MIT Kerberos 5 1.5
-
MIT 2006-002-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2006-002-patch.txt.asc
MIT Kerberos 5 1.5.1
-
MIT 2006-002-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2006-002-patch.txt.asc
Apple Mac OS X Server 10.4.9
-
Apple Security Update 2007-004 (Universal)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=13659&cat= 1&platform=osx&method=sa/SecUpd2007-004Univ.dmg
Apple Mac OS X 10.4.9
-
Apple Security Update 2007-004 (Universal)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=13659&cat= 1&platform=osx&method=sa/SecUpd2007-004Univ.dmg
References
MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability
References:
References:
- CERT: VU#481564 (US-CERT)
- Kerberos Homepage (MIT)
- MITKRB5-SA-2006-002: kadmind (via RPC lib) calls uninitialized function pointer ([email protected])
- APPLE-SA-2007-04-19 Security Update 2007-004 (Apple)
- Fedora Core 5 Update: krb5-1.4.3-5.3 (RedHat)
- Fedora Core 6 Update: krb5-1.5-13 (RedHat)
- OpenPKG-SA-2007.006 (OpenPKG)