Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2012:0042-1 Important: krb5 Remote Code Execution Advisory

suse
Calendar Grey January 5, 2012
Dist Suse Esm H88
SUSE Security Patch for OpenSSL addresses various vulnerabilities: critical update, denial of service, data exposure risk.
An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes ...

Summary

This update of krb5 fixes several security issues. * CVE-2011-4862: A remote code execution in the kerberized telnet daemon was fixed. (This only affects the ktelnetd from the krb5-appl RPM, not the regular telnetd supplied by SUSE.) * CVE-2011-1526 / MITKRB5-SA-2011-005: Fixed krb5 ftpd unauthorized file access problems. * CVE-2010-1323 / MITKRB5-SA-2010-007: Fixed multiple checksum handling vulnerabilities, where: o krb5 clients might have accepted unkeyed SAM-2 challenge checksums o krb5 might have accepted KRB-SAFE checksums with low-entropy derived keys * CVE-2010-1321, MITKRB5-SA-2010-005: Fixed GSS-API library null pointer dereference Security Issue reference: * CVE-2011-4862 Indications: Please install this update.

References

#596826 #650650 #698471 #738632

Cross- CVE-2011-4862

Affected Products:

SUSE Linux Enterprise Server 10 SP2

https://www.suse.com/security/cve/CVE-2011-4862.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0042-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here