MIT Kerberos Administration Daemon RPC Library Free Pointer Remote Code Execution Vulnerability
BID:24655
Info
MIT Kerberos Administration Daemon RPC Library Free Pointer Remote Code Execution Vulnerability
| Bugtraq ID: | 24655 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-2442 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2007 12:00AM |
| Updated: | Jun 24 2010 10:58AM |
| Credit: | Wei Wang of McAfee Avert Labs is credited with the discovery of this vulnerability. |
| Vulnerable: |
VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.0 VMWare ESX Server 2.5.4 Patch 5 VMWare ESX Server 2.5.4 Patch 3 VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.4 VMWare ESX Server 2.5.3 Patch 8 VMWare ESX Server 2.5.3 Patch 7 VMWare ESX Server 2.5.3 Patch 6 VMWare ESX Server 2.5.3 Patch 5 VMWare ESX Server 2.5.3 Patch 4 VMWare ESX Server 2.5.3 VMWare ESX Server 2.1.3 Patch 5 VMWare ESX Server 2.1.3 Patch 2 VMWare ESX Server 2.1.3 VMWare ESX Server 2.0.2 Patch 5 VMWare ESX Server 2.0.2 Patch 4 VMWare ESX Server 2.0.2 Patch 2 VMWare ESX Server 2.0.2 VMWare ESX Server 2.5.3 Patch 2 VMWare ESX Server 2.1.3 Patch 1 VMWare ESX Server 2.0.2 Patch 1 VMWare ESX 2.1.3 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 x86 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux Appliance Server 2.0 Trustix Secure Linux 3.0.5 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux 10.1 SuSE Linux 10.0 Sun Solaris 10_x86 Sun Solaris 10_sparc SGI ProPack 3.0 SP6 S.u.S.E. openSUSE 10.2 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat arpwatch-2.1a11-1.i386.rpm Redhat Advanced Workstation for the Itanium Processor 2.1 Novell KDC (Key Distribution Center) 1.0.2 Novell KDC (Key Distribution Center) 1.0 MIT Kerberos 5 1.6.1 MIT Kerberos 5 1.6 MIT Kerberos 5 1.5.4 MIT Kerberos 5 1.5.3 MIT Kerberos 5 1.5.2 MIT Kerberos 5 1.5.1 MIT Kerberos 5 1.5 MIT Kerberos 5 1.4.3 MIT Kerberos 5 1.4.2 MIT Kerberos 5 1.4.1 MIT Kerberos 5 1.4 MIT Kerberos 5 1.3.6 MIT Kerberos 5 1.3.5 MIT Kerberos 5 1.3.4 MIT Kerberos 5 1.3.3 MIT Kerberos 5 1.3.2 MIT Kerberos 5 1.3.1 MIT Kerberos 5 1.3 -alpha1 MIT Kerberos 5 1.3 MIT Kerberos 5 1.2.8 MIT Kerberos 5 1.2.7 MIT Kerberos 5 1.2.6 MIT Kerberos 5 1.2.5 MIT Kerberos 5 1.2.4 MIT Kerberos 5 1.2.3 MIT Kerberos 5 1.2.2 -beta1 MIT Kerberos 5 1.2.2 MIT Kerberos 5 1.2.1 MIT Kerberos 5 1.2 MIT Kerberos 5 1.1.1 MIT Kerberos 5 1.1 MIT Kerberos 5 1.0.8 MIT Kerberos 5 1.0.6 MIT Kerberos 5 1.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server MM3.0 Avaya Message Networking MN 3.1 Avaya Message Networking Avaya Aura Application Enablement Services 4.0 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.10 Apple Mac OS X 10.3.9 |
| Not Vulnerable: |
VMWare ESX Server 2.5.4 Patch 10 VMWare ESX Server 2.5.3 Patch 13 VMWare ESX Server 2.1.3 Patch 8 VMWare ESX Server 2.0.2 Patch 8 Novell KDC (Key Distribution Center) 1.0.3 MIT Kerberos 5 1.6.2 |
Discussion
MIT Kerberos Administration Daemon RPC Library Free Pointer Remote Code Execution Vulnerability
MIT Kerberos 5 Administration Daemon ('kadmind') is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with superuser privileges, completely compromising affected computers. Failed exploit attempts will likely result in denial-of-service conditions.
All 'kadmind' servers run on the master Kerberos server. Since the master server holds the KDC principal and policy database, an attack may not only compromise the affected computer, but could also compromise multiple hosts that use the server for authentication.
This issue also affects third-party applications using the affected RPC library.
Versions prior to 'kadmind' krb5-1.6.1 are vulnerable.
MIT Kerberos 5 Administration Daemon ('kadmind') is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with superuser privileges, completely compromising affected computers. Failed exploit attempts will likely result in denial-of-service conditions.
All 'kadmind' servers run on the master Kerberos server. Since the master server holds the KDC principal and policy database, an attack may not only compromise the affected computer, but could also compromise multiple hosts that use the server for authentication.
This issue also affects third-party applications using the affected RPC library.
Versions prior to 'kadmind' krb5-1.6.1 are vulnerable.
Exploit / POC
MIT Kerberos Administration Daemon RPC Library Free Pointer Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
MIT Kerberos Administration Daemon RPC Library Free Pointer Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and a patch to address this issue. Please see the references for more information.
Turbolinux Turbolinux 10 F...
TurboLinux Multimedia
MIT Kerberos 5 1.0
MIT Kerberos 5 1.0.6
MIT Kerberos 5 1.0.8
MIT Kerberos 5 1.1
MIT Kerberos 5 1.1.1
MIT Kerberos 5 1.2
MIT Kerberos 5 1.2.5
MIT Kerberos 5 1.2.8
MIT Kerberos 5 1.3.1
MIT Kerberos 5 1.3.3
MIT Kerberos 5 1.3.4
MIT Kerberos 5 1.3.5
MIT Kerberos 5 1.3.6
MIT Kerberos 5 1.4.2
MIT Kerberos 5 1.5
MIT Kerberos 5 1.5.1
MIT Kerberos 5 1.5.2
MIT Kerberos 5 1.5.3
MIT Kerberos 5 1.5.4
Turbolinux Turbolinux Desktop 10.0
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.3.9
Apple Mac OS X 10.4.10
SGI ProPack 3.0 SP6
Trustix Secure Linux 3.0
Trustix Secure Linux 3.0.5
Solution:
The vendor has released an advisory and a patch to address this issue. Please see the references for more information.
Turbolinux Turbolinux 10 F...
-
Turbolinux krb5-devel-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-devel-1.2.5-22.i586.rpm -
Turbolinux krb5-libs-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-libs-1.2.5-22.i586.rpm -
Turbolinux krb5-server-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-server-1.2.5-22.i586.rpm -
Turbolinux krb5-workstation-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-workstation-1.2.5-22.i586.rpm
TurboLinux Multimedia
-
Turbolinux krb5-devel-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-devel-1.2.5-22.i586.rpm -
Turbolinux krb5-libs-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-libs-1.2.5-22.i586.rpm -
Turbolinux krb5-server-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-server-1.2.5-22.i586.rpm -
Turbolinux krb5-workstation-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-workstation-1.2.5-22.i586.rpm
MIT Kerberos 5 1.0
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.0.6
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.0.8
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.1
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.1.1
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.2
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.2.5
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.2.8
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.3.1
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.3.3
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.3.4
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.3.5
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.3.6
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.4.2
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.5
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.5.1
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.5.2
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.5.3
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
MIT Kerberos 5 1.5.4
-
MIT 2007-004-patch.txt.asc
http://web.mit.edu/kerberos/advisories/2007-004-patch.txt.asc
Turbolinux Turbolinux Desktop 10.0
-
Turbolinux krb5-devel-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-devel-1.2.5-22.i586.rpm -
Turbolinux krb5-libs-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-libs-1.2.5-22.i586.rpm -
Turbolinux krb5-server-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-server-1.2.5-22.i586.rpm -
Turbolinux krb5-workstation-1.2.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/krb5-workstation-1.2.5-22.i586.rpm
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2007-007Pan.dmg For Mac OS X Server v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.3.9
-
Apple SecUpd2007-007Pan.dmg For Mac OS X v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.10
-
Apple SecUpd2007-007Ti.dmg For Mac OS X v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpd2007-007Univ.dmg For Mac OS X v10.4.10 (Universal)
http://www.apple.com/support/downloads/
SGI ProPack 3.0 SP6
-
SGI Patch 10421
ftp://oss.sgi.com/projects/sgi_propack/download/
Trustix Secure Linux 3.0
-
Trustix kerberos5-1.4.1-9tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix kerberos5-devel-1.4.1-9tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix kerberos5-libs-1.4.1-9tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/
Trustix Secure Linux 3.0.5
-
Trustix kerberos5-1.4.3-5tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix kerberos5-devel-1.4.3-5tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix kerberos5-libs-1.4.3-5tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/
References
MIT Kerberos Administration Daemon RPC Library Free Pointer Remote Code Execution Vulnerability
References:
References:
- HPSBUX02544 SSRT100107 rev.1 - HP-UX Running Kerberos, Remote Denial of Service (HP)
- Kerberos Homepage (MIT)
- Sun Alert ID: 102918 - Security Vulnerabilities in the KSSL Kernel Module May Le (Sun Microsystems)
- MITKRB5-SA-2007-004: kadmind multiple RPC lib vulnerabilities (MIT)
- ASA-2007-294 krb5 security update (RHSA-2007-0562) (Avaya)
- MIT krb5 Security Advisory 2007-004 (MIT)
- RHSA-2007:0384-4: krb5 security update (Red Hat)
- RHSA-2007:0562-2: krb5 security update (Red Hat)
- Security Vulnerability: kadmind affected by multiple RPC library vulnerabilities (Novell)
- VU#356961 MIT Kerberos kadmind RPC library gssrpc__svcauth_gssapi() uninitialize (US-CERT)