Oval Definition:oval:com.redhat.rhsa:def:20050330
Revision Date:2005-03-30Version:502
Title:RHSA-2005:330: krb5 security update (Important)
Description:Kerberos is a networked authentication system which uses a trusted third party (a KDC) to authenticate clients and servers to each other.

The krb5-workstation package includes a Kerberos-aware telnet client. Two buffer overflow flaws were discovered in the way the telnet client handles messages from a server. An attacker may be able to execute arbitrary code on a victim's machine if the victim can be tricked into connecting to a malicious telnet server. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2005-0468 and CAN-2005-0469 to these issues.

Users of krb5 should update to these erratum packages which contain a backported patch to correct this issue.

Red Hat would like to thank iDEFENSE for their responsible disclosure of this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2005-0468
CVE-2005-0469
RHSA-2005:330-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • krb5-libs is earlier than 0:1.2.7-42
  • AND krb5-libs is signed with Red Hat master key
  • krb5-devel is earlier than 0:1.2.7-42
  • AND krb5-devel is signed with Red Hat master key
  • krb5-server is earlier than 0:1.2.7-42
  • AND krb5-server is signed with Red Hat master key
  • krb5 is earlier than 0:1.2.7-42
  • AND krb5 is signed with Red Hat master key
  • krb5-workstation is earlier than 0:1.2.7-42
  • AND krb5-workstation is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • krb5-libs is earlier than 0:1.3.4-12
  • AND krb5-libs is signed with Red Hat master key
  • krb5-devel is earlier than 0:1.3.4-12
  • AND krb5-devel is signed with Red Hat master key
  • krb5-server is earlier than 0:1.3.4-12
  • AND krb5-server is signed with Red Hat master key
  • krb5 is earlier than 0:1.3.4-12
  • AND krb5 is signed with Red Hat master key
  • krb5-workstation is earlier than 0:1.3.4-12
  • AND krb5-workstation is signed with Red Hat master key
  • BACK