RHSA-2007:0858: Important: krb5 security update
Kerberos is a network authentication system which allows clients andservers to authenticate to each other through use of symmetric encryptionand a trusted third party, the KDC. kadmind is the KADM5 administrationserver.Tenable Network Security discovered a stack buffer overflow flaw in the RPClibrary used by kadmind. A remote unauthenticated attacker who can accesskadmind could trigger this flaw and cause kadmind to crash. On Red HatEnterprise Linux 5 it is not possible to exploit this flaw to run arbitrarycode as the overflow is blocked by FORTIFYSOURCE. (CVE-2007-3999)Garrett Wollman discovered an uninitialized pointer flaw in kadmind. Aremote unauthenticated attacker who can access kadmind could trigger thisflaw and cause kadmind to crash. (CVE-2007-4000)These issues did not affect the versions of Kerberos distributed with RedHat Enterprise Linux 2.1, 3, or 4.Users of krb5-server are advised to update to these erratum packages whichcontain backported fixes to correct these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2007:0858?
The severity of RHSA-2007:0858 is classified as important.
How do I fix RHSA-2007:0858?
To fix RHSA-2007:0858, update your Kerberos packages to the latest version provided in the security advisory.
What systems are affected by RHSA-2007:0858?
RHSA-2007:0858 primarily affects systems running vulnerable versions of Kerberos and kadmind.
What kind of vulnerability is addressed by RHSA-2007:0858?
RHSA-2007:0858 addresses a stack buffer overflow vulnerability in kadmind.
Is there a workaround for RHSA-2007:0858?
There is no official workaround for RHSA-2007:0858; applying the update is the recommended solution.