Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE 11.4: 2011:1169-1 Important: Kdc DoS and File Access

opensuse
Calendar Grey October 24, 2011
Dist Opensuse Esm H88
Key announcement regarding openSUSE krb5 to fix severe kdc service disruptions and prevent unauthorized access incidents.
An update that fixes three vulnerabilities is now available

Description

The following issues have been fixed:

- CVE-2011-1528: In releases krb5-1.8 and later, the KDC

can crash due to an assertion failure.

- CVE-2011-1529: In releases krb5-1.8 and later, the KDC

can crash due to a null pointer dereference.

Both bugs could be triggered by unauthenticated remote

attackers. Additionally CVE-2011-1526 was fixed that

allowed authenticated users to access files via krb5 ftpd

they should not have access to.

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch krb5-5303

- openSUSE 11.3:

zypper in -t patch krb5-5303

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

krb5-1.8.3-16.19.1

krb5-appl-clients-1.0-7.10.1

krb5-appl-servers-1.0-7.10.1

krb5-client-1.8.3-16.19.1

krb5-devel-1.8.3-16.19.1

krb5-plugin-kdb-ldap-1.8.3-16.19.1

krb5-plugin-preauth-pkinit-1.8.3-16.19.1

krb5-server-1.8.3-16.19.1

- openSUSE 11.4 (x86_64):

krb5-32bit-1.8.3-16.19.1

krb5-devel-32bit-1.8.3-16.19.1

- openSUSE 11.3 (i586 x86_64):

krb5-1.8.1-5.11.1

krb5-appl-clients-1.0-4.3.1

krb5-appl-servers-1.0-4.3.1

krb5-client-1.8.1-5.11.1

krb5-devel-1.8.1-5.11.1

krb5-plugin-kdb-ldap-1.8.1-5.11.1

krb5-plugin-preauth-pkinit-1.8.1-5.11.1

krb5-server-1.8.1-5.11.1

- openSUSE 11.3 (x86_64):

krb5-32bit-1.8.1-5.11.1

krb5-devel-32bit-1.8.1-5.11.1

References

https://www.suse.com/security/cve/CVE-2011-1526.html

https://www.suse.com/security/cve/CVE-2011-1528.html

https://www.suse.com/security/cve/CVE-2011-1529.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2011:1169-1
Rating: important
Affected Products: openSUSE 11.4 openSUSE 11.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here