It is currently Sun May 19, 2013 8:07 pm

All times are UTC




Post new topic Reply to topic  [ 2 posts ] 
Author Message
 Post subject: [CVE-2009-0845] krb5 <= 1.6.3, remote denial of service
PostPosted: Mon Mar 30, 2009 1:21 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
CVE-2009-0845 wrote:
The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token.


This is fixed in upstream svn:
http://src.mit.edu/fisheye/browse/krb5/ ... 5&r2=22084

More information can be found here:
http://krbdev.mit.edu/rt/Ticket/Display ... st&id=6402

We currently have version 1.6.3 in both types of repo.

Refernces:
http://web.nvd.nist.gov/view/vuln/detai ... -2009-0845
http://www.securityfocus.com/bid/34257

!8!


 Profile Send private message  
 
 Post subject: Re: [CVE-2009-0845] krb5 <= 1.6.3, remote denial of service
PostPosted: Wed Apr 08, 2009 1:19 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
Official SA:
http://web.mit.edu/kerberos/advisories/ ... 09-001.txt

And here is another security issue:

http://web.mit.edu/kerberos/advisories/ ... 09-002.txt

They are both to be fixed in upcoming 1.6.4 and 1.7 release.


 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

All times are UTC


 Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
 
cron