Oval Definition:oval:com.redhat.rhsa:def:20060746
Revision Date:2006-12-06Version:635
Title:RHSA-2006:0746: mod_auth_kerb security update (Low)
Description:mod_auth_kerb is module for the Apache HTTP Server designed to provide Kerberos authentication over HTTP.

An off by one flaw was found in the way mod_auth_kerb handles certain Kerberos authentication messages. A remote client could send a specially crafted authentication request which could crash an httpd child process (CVE-2006-5989).

A bug in the handling of multiple realms configured using the "KrbAuthRealms" directive has also been fixed.

All users of mod_auth_kerb should upgrade to these updated packages, which contain backported patches that resolve these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2006-5989
RHSA-2006:0746
RHSA-2006:0746-01
RHSA-2006:0746-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND mod_auth_kerb is earlier than 0:5.0-1.3
  • AND mod_auth_kerb is signed with Red Hat redhatrelease2 key
  • BACK