MIT Kerberos 5 KDC Multiple Memory Corruption Based Information Disclosure Vulnerabilities
BID:28303
Info
MIT Kerberos 5 KDC Multiple Memory Corruption Based Information Disclosure Vulnerabilities
| Bugtraq ID: | 28303 |
| Class: | Unknown |
| CVE: |
CVE-2008-0062 CVE-2008-0063 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2008 12:00AM |
| Updated: | Apr 13 2015 09:38PM |
| Credit: | The vendor disclosed these issues. |
| Vulnerable: |
VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.0 VMWare ESX Server 2.5.5 patch 6 VMWare ESX Server 2.5.5 patch 4 VMWare ESX Server 2.5.5 patch 2 VMWare ESX Server 2.5.5 VMWare ESX Server 2.5.4 Patch 5 VMWare ESX Server 2.5.4 Patch 3 VMWare ESX Server 2.5.4 Patch 17 VMWare ESX Server 2.5.4 Patch 16 VMWare ESX Server 2.5.4 patch 15 VMWare ESX Server 2.5.4 patch 13 VMWare ESX Server 2.5.4 Patch 10 VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.4 VMWare ESX Server 3.5 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 11 x64 Turbolinux Turbolinux Server 11 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE Suse Linux Enterprise Desktop 10 SP1 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 rPath Appliance Platform Linux Service 1 Redhat Linux Advanced Workstation 2.1 for the Ita 2.1 IA64 Redhat Fedora 7 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4.5.z Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4.5.z Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Novell Open Enterprise Server (OES) 0 Novell Open Enterprise Server 2 MIT Kerberos 5 1.6.3 MIT Kerberos 5 1.6.2 MIT Kerberos 5 1.5.2 MIT Kerberos 5 1.4.3 MIT Kerberos 5 1.3 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 HP Kerberos for OpenVMS 3.1 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Aura Application Enablement Services 3.1.4 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.4.11 Apple Mac OS X 10.5.2 Apple Mac OS X 10.4.11 |
| Not Vulnerable: |
VMWare ESX Server 2.5.5 patch 8 VMWare ESX Server 2.5.4 patch 19 HP Kerberos for OpenVMS 3.2 |
Discussion
MIT Kerberos 5 KDC Multiple Memory Corruption Based Information Disclosure Vulnerabilities
MIT Kerberos 5 KDC is prone to multiple information-disclosure vulnerabilities resulting from memory corruption.
These issues occur when KDC is configured to support Kerberos 4 and processes malformed krb4 messages.
An attacker can exploit these issues to obtain potentially sensitive information that will aid in further attacks. Failed exploit attempts will likely result in denial-of-service conditions. Given the nature of these vulnerabilities, the attacker could leverage these issues to execute arbitrary code, but this has not been confirmed.
MIT Kerberos 5 version 1.6.3 KDC is vulnerable; other versions may also be affected.
MIT Kerberos 5 KDC is prone to multiple information-disclosure vulnerabilities resulting from memory corruption.
These issues occur when KDC is configured to support Kerberos 4 and processes malformed krb4 messages.
An attacker can exploit these issues to obtain potentially sensitive information that will aid in further attacks. Failed exploit attempts will likely result in denial-of-service conditions. Given the nature of these vulnerabilities, the attacker could leverage these issues to execute arbitrary code, but this has not been confirmed.
MIT Kerberos 5 version 1.6.3 KDC is vulnerable; other versions may also be affected.
Exploit / POC
MIT Kerberos 5 KDC Multiple Memory Corruption Based Information Disclosure Vulnerabilities
The vendor states that proof-of-concept exploits are available. Please see the references for more information.
The vendor states that proof-of-concept exploits are available. Please see the references for more information.
Solution / Fix
MIT Kerberos 5 KDC Multiple Memory Corruption Based Information Disclosure Vulnerabilities
Solution:
The vendor has released an advisory and a patch to address this issue. Please see the references for more information.
MIT Kerberos 5 1.6.3
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.2
Solution:
The vendor has released an advisory and a patch to address this issue. Please see the references for more information.
MIT Kerberos 5 1.6.3
-
MIT 2008-001-patch.txt
http://web.mit.edu/kerberos/advisories/2008-001-patch.txt
Apple Mac OS X 10.4.11
-
Apple SecUpd2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002PPC.dmg -
Apple SecUpd2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002Univ.dmg
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002PPC.dmg -
Apple SecUpdSrvr2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002Univ.dmg
Apple Mac OS X 10.5.2
References
MIT Kerberos 5 KDC Multiple Memory Corruption Based Information Disclosure Vulnerabilities
References:
References:
- Kerberos Homepage (MIT)
- MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc ([email protected] )
- 5022520: novell-kerberos 20080331 (Novell)
- 5022542: novell-kerberos 20080331 (Novell)
- ASA-2008-144 krb5 security update (RHSA-2008-0181) (Avaya)
- RHSA-2008:0164-6 Critical: krb5 security and bugfix update (Red Hat)
- RHSA-2008:0180-4 Critical: krb5 security update (Red Hat)
- RHSA-2008:0181-3 Critical: krb5 security update (Red Hat)
- RHSA-2008:0182-3 Security Advisory Critical: krb5 security update (Red Hat)
- Vulnerability Note VU#895609 MIT Kerberos krb4-enabled KDC contains multiple vul (US-CERT)