Oval Definition:oval:com.redhat.rhsa:def:20121131
Revision Date:2012-07-31Version:635
Title:RHSA-2012:1131: krb5 security update (Important)
Description:Kerberos is a network authentication system which allows clients and servers to authenticate to each other using symmetric encryption and a trusted third-party, the Key Distribution Center (KDC).

  • An uninitialized pointer use flaw was found in the way the MIT Kerberos KDC handled initial authentication requests (AS-REQ). A remote, unauthenticated attacker could use this flaw to crash the KDC via a specially-crafted AS-REQ request. (CVE-2012-1015)

  • A NULL pointer dereference flaw was found in the MIT Kerberos administration daemon, kadmind. A Kerberos administrator who has the "create" privilege could use this flaw to crash kadmind. (CVE-2012-1013)

    Red Hat would like to thank the MIT Kerberos project for reporting CVE-2012-1015. Upstream acknowledges Emmanuel Bouillon (NCI Agency) as the original reporter of CVE-2012-1015.

    All krb5 users should upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, the krb5kdc and kadmind daemons will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-1013
    CVE-2012-1013
    CVE-2012-1015
    CVE-2012-1015
    RHSA-2012:1131
    RHSA-2012:1131-01
    RHSA-2012:1131-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • krb5-devel is earlier than 0:1.9-33.el6_3.2
  • AND krb5-devel is signed with Red Hat redhatrelease2 key
  • krb5-libs is earlier than 0:1.9-33.el6_3.2
  • AND krb5-libs is signed with Red Hat redhatrelease2 key
  • krb5-pkinit-openssl is earlier than 0:1.9-33.el6_3.2
  • AND krb5-pkinit-openssl is signed with Red Hat redhatrelease2 key
  • krb5-server is earlier than 0:1.9-33.el6_3.2
  • AND krb5-server is signed with Red Hat redhatrelease2 key
  • krb5-server-ldap is earlier than 0:1.9-33.el6_3.2
  • AND krb5-server-ldap is signed with Red Hat redhatrelease2 key
  • krb5-workstation is earlier than 0:1.9-33.el6_3.2
  • AND krb5-workstation is signed with Red Hat redhatrelease2 key
  • BACK