Oval Definition:oval:com.redhat.rhsa:def:20040236
Revision Date:2004-06-09Version:502
Title:RHSA-2004:236: krb5 security update (Moderate)
Description:Kerberos is a network authentication system.

Bugs have been fixed in the krb5_aname_to_localname library function. Specifically, buffer overflows were possible for all Kerberos versions up to and including 1.3.3. The krb5_aname_to_localname function translates a Kerberos principal name to a local account name, typically a UNIX username. This function is frequently used when performing authorization checks.

If configured with mappings from particular Kerberos principals to particular UNIX user names, certain functions called by krb5_aname_to_localname will not properly check the lengths of buffers used to store portions of the principal name. If configured to map principals to user names using rules, krb5_aname_to_localname would consistently write one byte past the end of a buffer allocated from the heap. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0523 to this issue.

Only configurations which enable the explicit mapping or rules-based mapping functionality of krb5_aname_to_localname() are vulnerable. These configurations are not the default.

Users of Kerberos are advised to upgrade to these erratum packages which contain backported security patches to correct these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2004-0523
RHSA-2004:236-01
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND Package Information
  • krb5-libs is earlier than 0:1.2.7-24
  • AND krb5-libs is signed with Red Hat master key
  • OR
  • krb5-devel is earlier than 0:1.2.7-24
  • AND krb5-devel is signed with Red Hat master key
  • OR
  • krb5-server is earlier than 0:1.2.7-24
  • AND krb5-server is signed with Red Hat master key
  • OR
  • krb5 is earlier than 0:1.2.7-24
  • AND krb5 is signed with Red Hat master key
  • OR
  • krb5-workstation is earlier than 0:1.2.7-24
  • AND krb5-workstation is signed with Red Hat master key
  • BACK