|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
A remote overflow exists in Kerberos 5. Kerberos fails to check the string length in the functions aname_replacer(), do_replacement() and rule_an_to_ln() resulting in a heap buffer overflow. With a specially crafted request, an attacker can gain remote access as root resulting in a loss of confidentiality, integrity, and/or availability. This vulnerability only exists when the software is used with a non-standard configuration. Please see the MIT release notes for the details.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity,
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to Kerberos version 1.3.4 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the patch provided in the original MIT advisory.
|
|
Products |
|
Kerberos 5
 |
1.3.3 |
|
SEAM
 |
1.0.2 |
|
|
|
|
|
|
Credit |
- Christopher Nebergall -
- Nico Williams -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|