Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian Security Announcement DSA-2129-1: Serious KRB5 Checksum Issue

debian
Calendar Grey December 1, 2010
Debian Logo
Important Debian notice reveals vulnerability in krb5 checksums. Immediate upgrade suggested to address security threat.
A vulnerability has been found in krb5, the MIT implementation of Kerberos

Summary

MIT krb5 clients incorrectly accept an unkeyed checksums in the SAM-2
preauthentication challenge: An unauthenticated remote attacker could
alter a SAM-2 challenge, affecting the prompt text seen by the user or
the kind of response sent to the KDC. Under some circumstances, this
can negate the incremental security benefit of using a single-use
authentication mechanism token.

MIT krb5 incorrectly accepts RFC 3961 key-derivation checksums using
RC4 keys when verifying KRB-SAFE messages: An unauthenticated remote
attacker has a 1/256 chance of forging KRB-SAFE messages in an
application protocol if the targeted pre-existing session uses an RC4
session key. Few application protocols use KRB-SAFE messages.

The Common Vulnerabilities and Exposures project has assigned
CVE-2010-1323 to these issues.

For the stable distribution (lenny), these problems have been fixed in
version 1.6.dfsg.4~beta1-5lenny6.

The builds for the mips architecture are not included in this advisory.
They will be released as soon as...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here