Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian 1.8.3+dfsg-4squeeze5 Critical: KDC Denial Of Service

debian
Calendar Grey January 4, 2012
Debian Logo
Urgent patch release for OpenSSH in Ubuntu tackling remote code execution risks. Immediate upgrade advised.
It was discovered that the Key Distribution Center (KDC) in Kerberos 5 crashes when processing certain crafted requests: CVE-2011-1528

Summary

It was discovered that the Key Distribution Center (KDC) in Kerberos 5
crashes when processing certain crafted requests:

CVE-2011-1528
When the LDAP backend is used, remote users can trigger
a KDC daemon crash and denial of service.

CVE-2011-1529
When the LDAP or Berkeley DB backend is used, remote users can trigger a NULL pointer dereference in the KDC daemon
and a denial of service.

The oldstable distribution (lenny) is not affected by these problems.

For the stable distribution (squeeze), these problems have been fixed
in version 1.8.3+dfsg-4squeeze5.

For the testing distribution (wheezy) and the unstable distribution
(sid), these problems have been fixed in version 1.10+dfsg~alpha1-1.

We recommend that you upgrade your krb5 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: krb5
CVE ID: CVE-2011-1528 CVE-2011-1529

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here