Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 11.10 USN-1233-1 Critical: Kerberos Denial Of Service Issue

ubuntu
Calendar Grey October 18, 2011
Scroller Ubuntu
Multiple denial of service vulnerabilities resolved in Kerberos KDC, impacting Ubuntu 10.04 LTS and newer releases. Upgrade promptly.
Several denial of service issues were fixed in the Kerberos KeyDistribution Center (KDC).

Summary

Several denial of service issues were fixed in the Kerberos Key

Distribution Center (KDC).

Software Description:

- krb5: MIT Kerberos Network Authentication Protocol

Details:

Nalin Dahyabhai, Andrej Ota and Kyle Moffett discovered a NULL

pointer dereference in the KDC LDAP backend. An unauthenticated

remote attacker could use this to cause a denial of service. This

issue affected Ubuntu 11.10. (CVE-2011-1527)

Mark Deneen discovered that an assert() could be triggered in the

krb5_ldap_lockout_audit() function in the KDC LDAP backend and

the krb5_db2_lockout_audit() function in the KDC DB2 backend. An

unauthenticated remote attacker could use this to cause a denial of

service. (CVE-2011-1528)

It was discovered that a NULL pointer dereference could occur in the

lookup_lockout_policy() function in the KDC LDAP and DB2 backends.

An unauthenticated remote attacker could use this to cause a denial of

service. (CVE-2011-1529)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  krb5-kdc                        1.9.1+dfsg-1ubuntu1.1
  krb5-kdc-ldap                   1.9.1+dfsg-1ubuntu1.1

Ubuntu 11.04:
  krb5-kdc                        1.8.3+dfsg-5ubuntu2.2
  krb5-kdc-ldap                   1.8.3+dfsg-5ubuntu2.2

Ubuntu 10.10:
  krb5-kdc                        1.8.1+dfsg-5ubuntu0.8
  krb5-kdc-ldap                   1.8.1+dfsg-5ubuntu0.8

Ubuntu 10.04 LTS:
  krb5-kdc                        1.8.1+dfsg-2ubuntu0.10
  krb5-kdc-ldap                   1.8.1+dfsg-2ubuntu0.10

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1233-1

CVE-2011-1527, CVE-2011-1528, CVE-2011-1529

Severity
critical
Lowest
Low
Medium
High
Critical

October 18, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.