Oval Definition:oval:com.redhat.rhsa:def:20110920
Revision Date:2011-07-05Version:639
Title:RHSA-2011:0920: krb5-appl security update (Important)
Description:The krb5-appl packages provide Kerberos-aware telnet, ftp, rcp, rsh, and rlogin clients and servers. While these have been replaced by tools such as OpenSSH in most environments, they remain in use in others.

  • It was found that gssftp, a Kerberos-aware FTP server, did not properly drop privileges. A remote FTP user could use this flaw to gain unauthorized read or write access to files that are owned by the root group. (CVE-2011-1526)

    Red Hat would like to thank the MIT Kerberos project for reporting this issue. Upstream acknowledges Tim Zingelman as the original reporter.

    All krb5-appl users should upgrade to these updated packages, which contain a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-1526
    CVE-2011-1526
    RHSA-2011:0920
    RHSA-2011:0920-01
    RHSA-2011:0920-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • krb5-appl-clients is earlier than 0:1.0.1-2.el6_1.1
  • AND krb5-appl-clients is signed with Red Hat redhatrelease2 key
  • krb5-appl-servers is earlier than 0:1.0.1-2.el6_1.1
  • AND krb5-appl-servers is signed with Red Hat redhatrelease2 key
  • BACK