MIT Kerberos 5 KAdminD Server Rename_Principal_2_SVC() Function Stack Buffer Overflow Vulnerability
BID:24653
Info
MIT Kerberos 5 KAdminD Server Rename_Principal_2_SVC() Function Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 24653 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-2798 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2007 12:00AM |
| Updated: | Jun 24 2010 10:58AM |
| Credit: | The discoverer of this vulnerability wishes to remain anonymous. |
| Vulnerable: |
VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.0 VMWare ESX Server 2.5.4 Patch 5 VMWare ESX Server 2.5.4 Patch 3 VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.4 VMWare ESX Server 2.5.3 Patch 8 VMWare ESX Server 2.5.3 Patch 7 VMWare ESX Server 2.5.3 Patch 6 VMWare ESX Server 2.5.3 Patch 5 VMWare ESX Server 2.5.3 Patch 4 VMWare ESX Server 2.5.3 VMWare ESX Server 2.1.3 Patch 5 VMWare ESX Server 2.1.3 Patch 2 VMWare ESX Server 2.1.3 VMWare ESX Server 2.0.2 Patch 5 VMWare ESX Server 2.0.2 Patch 4 VMWare ESX Server 2.0.2 Patch 2 VMWare ESX Server 2.0.2 VMWare ESX Server 2.5.3 Patch 2 VMWare ESX Server 2.1.3 Patch 1 VMWare ESX Server 2.0.2 Patch 1 VMWare ESX 2.1.3 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux Appliance Server 2.0 Trustix Secure Linux 3.0.5 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux 10.1 SuSE Linux 10.0 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun SEAM 1.0.1 SGI ProPack 3.0 SP6 S.u.S.E. openSUSE 10.2 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux Virtualization 5 Server Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Optional Productivity Application 5 server Redhat Enterprise Linux Hardware Certification 5 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Supplementary 5 client Redhat Enterprise Linux Desktop Multi OS 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux Clustering 5 server Redhat Enterprise Linux Cluster-Storage 5 server Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Novell KDC (Key Distribution Center) 1.0.2 Novell KDC (Key Distribution Center) 1.0 MIT Kerberos 5 1.6.1 MIT Kerberos 5 1.6 MIT Kerberos 5 1.5.3 MIT Kerberos 5 1.5.2 MIT Kerberos 5 1.5.1 MIT Kerberos 5 1.5 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server MM3.0 Avaya Message Networking MN 3.1 Avaya Message Networking Avaya Interactive Response 1.3 Avaya Interactive Response 2.0 Avaya Aura Application Enablement Services 4.0 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.10 Apple Mac OS X 10.3.9 |
| Not Vulnerable: |
VMWare ESX Server 2.5.4 Patch 10 VMWare ESX Server 2.5.3 Patch 13 VMWare ESX Server 2.1.3 Patch 8 VMWare ESX Server 2.0.2 Patch 8 Novell KDC (Key Distribution Center) 1.0.3 MIT Kerberos 5 1.6.2 MIT Kerberos 5 1.5.4 |
Discussion
MIT Kerberos 5 KAdminD Server Rename_Principal_2_SVC() Function Stack Buffer Overflow Vulnerability
Kerberos 5 'kadmind' (Kerberos Administration Daemon) server is prone to a stack-based buffer-overflow vulnerability because the software fails to adequately bounds-check user-supplied data before copying it to an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with administrative privileges. A successful attack can result in the complete compromise of the application. Failed attempts will likely result in denial-of-service conditions.
All 'kadmind' servers run on the master Kerberos server. Since the master server holds the KDC principal and policy database, an attack may not only compromise the affected computer, but could also compromise multiple hosts that use the server for authentication.
Kerberos 5 'kadmind' 1.6.1, 1.5.3, and prior versions are vulnerable.
Kerberos 5 'kadmind' (Kerberos Administration Daemon) server is prone to a stack-based buffer-overflow vulnerability because the software fails to adequately bounds-check user-supplied data before copying it to an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with administrative privileges. A successful attack can result in the complete compromise of the application. Failed attempts will likely result in denial-of-service conditions.
All 'kadmind' servers run on the master Kerberos server. Since the master server holds the KDC principal and policy database, an attack may not only compromise the affected computer, but could also compromise multiple hosts that use the server for authentication.
Kerberos 5 'kadmind' 1.6.1, 1.5.3, and prior versions are vulnerable.
Exploit / POC
MIT Kerberos 5 KAdminD Server Rename_Principal_2_SVC() Function Stack Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
MIT Kerberos 5 KAdminD Server Rename_Principal_2_SVC() Function Stack Buffer Overflow Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
Sun SEAM 1.0.1
MIT Kerberos 5 1.5.3
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.3.9
Apple Mac OS X 10.4.10
SGI ProPack 3.0 SP6
Trustix Secure Linux 3.0
Trustix Secure Linux 3.0.5
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
Sun SEAM 1.0.1
-
Sun 110060-22
SPARC platform
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -110060-22-1 -
Sun 110061-22
x86 platform
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -110061-22-1
MIT Kerberos 5 1.5.3
-
MIT 2007-005-patch.txt
http://web.mit.edu/kerberos/advisories/2007-005-patch.txt
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2007-007Pan.dmg For Mac OS X Server v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.3.9
-
Apple SecUpd2007-007Pan.dmg For Mac OS X v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.10
-
Apple SecUpd2007-007Ti.dmg For Mac OS X v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpd2007-007Univ.dmg For Mac OS X v10.4.10 (Universal)
http://www.apple.com/support/downloads/
SGI ProPack 3.0 SP6
-
SGI Patch 10421
ftp://oss.sgi.com/projects/sgi_propack/download/
Trustix Secure Linux 3.0
-
Trustix kerberos5-1.4.1-9tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix kerberos5-devel-1.4.1-9tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix kerberos5-libs-1.4.1-9tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/
Trustix Secure Linux 3.0.5
-
Trustix kerberos5-1.4.3-5tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix kerberos5-devel-1.4.3-5tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix kerberos5-libs-1.4.3-5tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/
References
MIT Kerberos 5 KAdminD Server Rename_Principal_2_SVC() Function Stack Buffer Overflow Vulnerability
References:
References:
- HPSBUX02544 SSRT100107 rev.1 - HP-UX Running Kerberos, Remote Denial of Service (HP)
- Kerberos Homepage (MIT)
- VU#554257 (US-CERT)
- iDefense Security Advisory 06.26.07: Multiple Vendor Kerberos kadmind ([email protected])
- MITKRB5-SA-2007-005: kadmind vulnerable to buffer overflow ([email protected])
- ASA-2007-294 krb5 security update (RHSA-2007-0562) (Avaya)
- Avaya Security Advisory ASA-2007-304: Security Vulnerability in the Kerberos Adm (Avaya Inc )
- Multiple Vendor Kerberos kadmind Rename Principal Buffer Overflow Vulnerability (iDefense Labs)
- RHSA-2007:0384-4: krb5 security update (Red Hat)
- RHSA-2007:0562-2: krb5 security update (Red Hat)
- Security Vulnerability: kadmind stack buffer overflow vulnerability (Novell)
- Sun Alert ID: 102985 Security Vulnerability in the Kerberos Administration Daemo (Sun)