USN-7257-1: Kerberos vulnerability
Goldberg, Miro Haller, Nadia Heninger, Mike Milano, Dan Shumow, Marc Stevens, and Adam Suhl discovered that Kerberos incorrectly authenticated certain responses. An attacker able to intercept communications between a RADIUS client and server could possibly use this issue to forge responses, bypass authentication, and access network devices and services. This update introduces support for the Message-Authenticator attribute in non-EAP authentication methods for communications between Kerberos and a RADIUS server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7257-1?
The USN-7257-1 vulnerability is considered high risk due to the potential for attackers to forge authentication responses.
How do I fix USN-7257-1?
To resolve USN-7257-1, update the affected packages to the recommended versions specific to your Ubuntu distribution.
What software is affected by USN-7257-1?
USN-7257-1 affects multiple versions of libk5crypto3 and libkrad0 on various Ubuntu releases.
What does USN-7257-1 exploit?
USN-7257-1 exploits a flaw in Kerberos that allows interception and forgery of authentication responses between RADIUS clients and servers.
How can I verify if I'm impacted by USN-7257-1?
You can check your installed versions of libk5crypto3 and libkrad0 against the versions listed in the USN-7257-1 advisory to determine if you are affected.