Oval Definition:oval:com.redhat.rhsa:def:20070095
Revision Date:2008-03-20Version:637
Title:RHSA-2007:0095: krb5 security update (Critical)
Description:Kerberos is a network authentication system which allows clients and servers to authenticate to each other through use of symmetric encryption and a trusted third party, the KDC.

  • A flaw was found in the username handling of the MIT krb5 telnet daemon (telnetd). A remote attacker who can access the telnet port of a target machine could log in as root without requiring a password. (CVE-2007-0956)

    Note that the krb5 telnet daemon is not enabled by default in any version of Red Hat Enterprise Linux. In addition, the default firewall rules block remote access to the telnet port. This flaw does not affect the telnet daemon distributed in the telnet-server package.

    For users who have enabled the krb5 telnet daemon and have it accessible remotely, this update should be applied immediately.

    Whilst we are not aware at this time that the flaw is being actively exploited, we have confirmed that the flaw is very easily exploitable.

    This update also fixes two additional security issues:

  • Buffer overflows were found which affect the Kerberos KDC and the kadmin server daemon. A remote attacker who can access the KDC could exploit this bug to run arbitrary code with the privileges of the KDC or kadmin server processes. (CVE-2007-0957)

  • A double-free flaw was found in the GSSAPI library used by the kadmin server daemon. Red Hat Enterprise Linux 4 and 5 contain checks within glibc that detect double-free flaws. Therefore, on Red Hat Enterprise Linux 4 and 5 successful exploitation of this issue can only lead to a denial of service. Applications which use this library in earlier releases of Red Hat Enterprise Linux may also be affected. (CVE-2007-1216)

    All users are advised to update to these erratum packages which contain a backported fix to correct these issues.

    Red Hat would like to thank MIT and iDefense for reporting these vulnerabilities.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-0956
    CVE-2007-0957
    CVE-2007-1216
    RHSA-2007:0095
    RHSA-2007:0095-01
    RHSA-2007:0095-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • krb5-server is earlier than 0:1.2.7-61
  • AND krb5-server is signed with Red Hat master key
  • krb5-devel is earlier than 0:1.2.7-61
  • AND krb5-devel is signed with Red Hat master key
  • krb5-libs is earlier than 0:1.2.7-61
  • AND krb5-libs is signed with Red Hat master key
  • krb5-workstation is earlier than 0:1.2.7-61
  • AND krb5-workstation is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • krb5-server is earlier than 0:1.3.4-46
  • AND krb5-server is signed with Red Hat master key
  • krb5-devel is earlier than 0:1.3.4-46
  • AND krb5-devel is signed with Red Hat master key
  • krb5-workstation is earlier than 0:1.3.4-46
  • AND krb5-workstation is signed with Red Hat master key
  • krb5-libs is earlier than 0:1.3.4-46
  • AND krb5-libs is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • krb5-workstation is earlier than 0:1.5-23
  • AND krb5-workstation is signed with Red Hat redhatrelease key
  • krb5-libs is earlier than 0:1.5-23
  • AND krb5-libs is signed with Red Hat redhatrelease key
  • krb5-devel is earlier than 0:1.5-23
  • AND krb5-devel is signed with Red Hat redhatrelease key
  • krb5-server is earlier than 0:1.5-23
  • AND krb5-server is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • krb5 is earlier than 0:1.2.7-61
  • AND krb5 is signed with Red Hat master key
  • krb5-devel is earlier than 0:1.2.7-61
  • AND krb5-devel is signed with Red Hat master key
  • krb5-libs is earlier than 0:1.2.7-61
  • AND krb5-libs is signed with Red Hat master key
  • krb5-server is earlier than 0:1.2.7-61
  • AND krb5-server is signed with Red Hat master key
  • krb5-workstation is earlier than 0:1.2.7-61
  • AND krb5-workstation is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • krb5 is earlier than 0:1.3.4-46
  • AND krb5 is signed with Red Hat master key
  • krb5-devel is earlier than 0:1.3.4-46
  • AND krb5-devel is signed with Red Hat master key
  • krb5-libs is earlier than 0:1.3.4-46
  • AND krb5-libs is signed with Red Hat master key
  • krb5-server is earlier than 0:1.3.4-46
  • AND krb5-server is signed with Red Hat master key
  • krb5-workstation is earlier than 0:1.3.4-46
  • AND krb5-workstation is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • krb5 is earlier than 0:1.5-23
  • AND krb5 is signed with Red Hat redhatrelease key
  • krb5-devel is earlier than 0:1.5-23
  • AND krb5-devel is signed with Red Hat redhatrelease key
  • krb5-libs is earlier than 0:1.5-23
  • AND krb5-libs is signed with Red Hat redhatrelease key
  • krb5-server is earlier than 0:1.5-23
  • AND krb5-server is signed with Red Hat redhatrelease key
  • krb5-workstation is earlier than 0:1.5-23
  • AND krb5-workstation is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • krb5-devel is earlier than 0:1.3.4-46
  • AND krb5-devel is signed with Red Hat redhatrelease2 key
  • krb5-libs is earlier than 0:1.3.4-46
  • AND krb5-libs is signed with Red Hat redhatrelease2 key
  • krb5-server is earlier than 0:1.3.4-46
  • AND krb5-server is signed with Red Hat redhatrelease2 key
  • krb5-workstation is earlier than 0:1.3.4-46
  • AND krb5-workstation is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • krb5-devel is earlier than 0:1.5-23
  • AND krb5-devel is signed with Red Hat redhatrelease2 key
  • krb5-libs is earlier than 0:1.5-23
  • AND krb5-libs is signed with Red Hat redhatrelease2 key
  • krb5-server is earlier than 0:1.5-23
  • AND krb5-server is signed with Red Hat redhatrelease2 key
  • krb5-workstation is earlier than 0:1.5-23
  • AND krb5-workstation is signed with Red Hat redhatrelease2 key
  • BACK