First published: Tue Apr 07 2009(Updated: )
Kerberos is a network authentication system which allows clients and<br>servers to authenticate to each other using symmetric encryption and a<br>trusted third party, the Key Distribution Center (KDC). The Generic<br>Security Service Application Program Interface (GSS-API) definition<br>provides security services to callers (protocols) in a generic fashion. The<br>Simple and Protected GSS-API Negotiation (SPNEGO) mechanism is used by<br>GSS-API peers to choose from a common set of security mechanisms.<br>An input validation flaw was found in the ASN.1 (Abstract Syntax Notation<br>One) decoder used by MIT Kerberos. A remote attacker could use this flaw to<br>crash a network service using the MIT Kerberos library, such as kadmind or<br>krb5kdc, by causing it to dereference or free an uninitialized pointer.<br>(CVE-2009-0846)<br>Multiple input validation flaws were found in the MIT Kerberos GSS-API<br>library's implementation of the SPNEGO mechanism. A remote attacker could<br>use these flaws to crash any network service utilizing the MIT Kerberos<br>GSS-API library to authenticate users or, possibly, leak portions of the<br>service's memory. (CVE-2009-0844, CVE-2009-0845)<br>All krb5 users should upgrade to these updated packages, which contain<br>backported patches to correct these issues. All running services using the<br>MIT Kerberos libraries must be restarted for the update to take effect.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/krb5 | <1.6.1-31.el5_3.3 | 1.6.1-31.el5_3.3 |
redhat/krb5-devel | <1.6.1-31.el5_3.3 | 1.6.1-31.el5_3.3 |
redhat/krb5-devel | <1.6.1-31.el5_3.3 | 1.6.1-31.el5_3.3 |
redhat/krb5-libs | <1.6.1-31.el5_3.3 | 1.6.1-31.el5_3.3 |
redhat/krb5-libs | <1.6.1-31.el5_3.3 | 1.6.1-31.el5_3.3 |
redhat/krb5-server | <1.6.1-31.el5_3.3 | 1.6.1-31.el5_3.3 |
redhat/krb5-workstation | <1.6.1-31.el5_3.3 | 1.6.1-31.el5_3.3 |
redhat/krb5-server | <1.6.1-31.el5_3.3 | 1.6.1-31.el5_3.3 |
redhat/krb5-workstation | <1.6.1-31.el5_3.3 | 1.6.1-31.el5_3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.