Oval Definition:oval:com.redhat.rhsa:def:20100029
Revision Date:2010-01-12Version:641
Title:RHSA-2010:0029: krb5 security update (Critical)
Description:Kerberos is a network authentication system which allows clients and servers to authenticate to each other using symmetric encryption and a trusted third party, the Key Distribution Center (KDC).

  • Multiple integer underflow flaws, leading to heap-based corruption, were found in the way the MIT Kerberos Key Distribution Center (KDC) decrypted ciphertexts encrypted with the Advanced Encryption Standard (AES) and ARCFOUR (RC4) encryption algorithms. If a remote KDC client were able to provide a specially-crafted AES- or RC4-encrypted ciphertext or texts, it could potentially lead to either a denial of service of the central KDC (KDC crash or abort upon processing the crafted ciphertext), or arbitrary code execution with the privileges of the KDC (i.e., root privileges). (CVE-2009-4212)

    All krb5 users should upgrade to these updated packages, which contain a backported patch to correct these issues. All running services using the MIT Kerberos libraries must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-4212
    RHSA-2010:0029
    RHSA-2010:0029-02
    RHSA-2010:0029-02
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • krb5-workstation is earlier than 0:1.2.7-71
  • AND krb5-workstation is signed with Red Hat master key
  • krb5-libs is earlier than 0:1.2.7-71
  • AND krb5-libs is signed with Red Hat master key
  • krb5-server is earlier than 0:1.2.7-71
  • AND krb5-server is signed with Red Hat master key
  • krb5-devel is earlier than 0:1.2.7-71
  • AND krb5-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • krb5-libs is earlier than 0:1.3.4-62.el4_8.1
  • AND krb5-libs is signed with Red Hat master key
  • krb5-workstation is earlier than 0:1.3.4-62.el4_8.1
  • AND krb5-workstation is signed with Red Hat master key
  • krb5-devel is earlier than 0:1.3.4-62.el4_8.1
  • AND krb5-devel is signed with Red Hat master key
  • krb5-server is earlier than 0:1.3.4-62.el4_8.1
  • AND krb5-server is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • krb5-libs is earlier than 0:1.6.1-36.el5_4.1
  • AND krb5-libs is signed with Red Hat redhatrelease key
  • krb5-devel is earlier than 0:1.6.1-36.el5_4.1
  • AND krb5-devel is signed with Red Hat redhatrelease key
  • krb5-server is earlier than 0:1.6.1-36.el5_4.1
  • AND krb5-server is signed with Red Hat redhatrelease key
  • krb5-workstation is earlier than 0:1.6.1-36.el5_4.1
  • AND krb5-workstation is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • krb5-devel is earlier than 0:1.3.4-62.el4_8.1
  • AND krb5-devel is signed with Red Hat redhatrelease2 key
  • krb5-libs is earlier than 0:1.3.4-62.el4_8.1
  • AND krb5-libs is signed with Red Hat redhatrelease2 key
  • krb5-server is earlier than 0:1.3.4-62.el4_8.1
  • AND krb5-server is signed with Red Hat redhatrelease2 key
  • krb5-workstation is earlier than 0:1.3.4-62.el4_8.1
  • AND krb5-workstation is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • krb5-devel is earlier than 0:1.6.1-36.el5_4.1
  • AND krb5-devel is signed with Red Hat redhatrelease2 key
  • krb5-libs is earlier than 0:1.6.1-36.el5_4.1
  • AND krb5-libs is signed with Red Hat redhatrelease2 key
  • krb5-server is earlier than 0:1.6.1-36.el5_4.1
  • AND krb5-server is signed with Red Hat redhatrelease2 key
  • krb5-workstation is earlier than 0:1.6.1-36.el5_4.1
  • AND krb5-workstation is signed with Red Hat redhatrelease2 key
  • BACK