Oval Definition:oval:org.mitre.oval:def:8094
Revision Date:2014-06-23Version:18
Title:DSA-1524 krb5 -- several vulnerabilities
Description:Several remote vulnerabilities have been discovered in the kdc component of the krb5, a system for authenticating users and services on a network. The Common Vulnerabilities and Exposures project identifies the following problems: An unauthenticated remote attacker may cause a krb4-enabled KDC to crash, expose information, or execute arbitrary code. Successful exploitation of this vulnerability could compromise the Kerberos key database and host security on the KDC host. An unauthenticated remote attacker may cause a krb4-enabled KDC to expose information. It is theoretically possible for the exposed information to include secret key data on some platforms. An unauthenticated remote attacker can cause memory corruption in the kadmind process, which is likely to cause kadmind to crash, resulting in a denial of service. It is at least theoretically possible for such corruption to result in database corruption or arbitrary code execution, though we have no such exploit and are not aware of any such exploits in use in the wild. In versions of MIT Kerberos shipped by Debian, this bug can only be triggered in configurations that allow large numbers of open file descriptors in a process.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-0062
CVE-2008-0063
CVE-2008-0947
DSA-1524
Platform(s):Debian GNU/Linux 3.1
Debian GNU/Linux 4.0
Product(s):krb5
Definition Synopsis
  • Release section
  • Debian GNU/Linux 4.0 is installed.
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND krb5-doc is earlier than 1.4.4-7etch5
  • OR krb5-rsh-server is earlier than 1.4.4-7etch5
  • OR krb5-telnetd is earlier than 1.4.4-7etch5
  • OR libkrb5-dev is earlier than 1.4.4-7etch5
  • OR libkrb53 is earlier than 1.4.4-7etch5
  • OR krb5-ftpd is earlier than 1.4.4-7etch5
  • OR krb5-admin-server is earlier than 1.4.4-7etch5
  • OR libkadm55 is earlier than 1.4.4-7etch5
  • OR libkrb5-dbg is earlier than 1.4.4-7etch5
  • OR krb5-user is earlier than 1.4.4-7etch5
  • OR krb5-clients is earlier than 1.4.4-7etch5
  • OR krb5-kdc is earlier than 1.4.4-7etch5
  • OR Release section
  • Debian GNU/Linux 3.1 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND krb5-doc is earlier than 1.3.6-2sarge6
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is m68k
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is ia64
  • OR Installed architecture is mips
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • krb5-rsh-server is earlier than 1.3.6-2sarge6
  • OR krb5-telnetd is earlier than 1.3.6-2sarge6
  • OR libkrb53 is earlier than 1.3.6-2sarge6
  • OR libkrb5-dev is earlier than 1.3.6-2sarge6
  • OR krb5-ftpd is earlier than 1.3.6-2sarge6
  • OR libkadm55 is earlier than 1.3.6-2sarge6
  • OR krb5-user is earlier than 1.3.6-2sarge6
  • OR krb5-kdc is earlier than 1.3.6-2sarge6
  • OR krb5-clients is earlier than 1.3.6-2sarge6
  • OR krb5-admin-server is earlier than 1.3.6-2sarge6
  • BACK