Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 9: MGASA-2024-0385 critical: krb5 forgery attack

mageia
Calendar Grey December 2, 2024
Dist Mageia Esm H88
Krb5 software revisions address spoofing attack flaw in Mageia. Crucial for users to apply updates without delay.
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any ot...

Summary

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. (CVE-2024-3596)

References

- https://bugs.mageia.org/show_bug.cgi?id=33769

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REJM7FX5TXBAJNRQ7XSMGPQSLMSSGMA3/

- https://www.cve.org/CVERecord?id=CVE-2024-3596

Resolution

SRPMS

- 9/core/krb5-1.20.1-1.3.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 02 Dec 2024
URL: https://advisories.mageia.org/MGASA-2024-0385.html
Type: security
CVE: CVE-2024-3596

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here