Oval Definition:oval:com.redhat.rhsa:def:20060612
Revision Date:2008-03-20Version:641
Title:RHSA-2006:0612: krb5 security update (Important)
Description:Kerberos is a network authentication system which allows clients and servers to authenticate to each other through use of symmetric encryption and a trusted third party, the KDC.

A flaw was found where some bundled Kerberos-aware applications would fail to check the result of the setuid() call. On Linux 2.6 kernels, the setuid() call can fail if certain user limits are hit. A local attacker could manipulate their environment in such a way to get the applications to continue to run as root, potentially leading to an escalation of privileges. (CVE-2006-3083).

Users are advised to update to these erratum packages which contain a backported fix to correct this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2006-3083
RHSA-2006:0612
RHSA-2006:0612-01
RHSA-2006:0612-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • krb5-devel is earlier than 0:1.3.4-33
  • AND krb5-devel is signed with Red Hat redhatrelease2 key
  • krb5-libs is earlier than 0:1.3.4-33
  • AND krb5-libs is signed with Red Hat redhatrelease2 key
  • krb5-server is earlier than 0:1.3.4-33
  • AND krb5-server is signed with Red Hat redhatrelease2 key
  • krb5-workstation is earlier than 0:1.3.4-33
  • AND krb5-workstation is signed with Red Hat redhatrelease2 key
  • BACK