Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
87

Debian: DSA-5287-1 Urgent Heimdal Denial Of Service Vulnerability

Several vulnerabilities were discovered in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. CVE-2021-3671 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5287-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 22, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : heimdal CVE ID : CVE-2021-3671 CVE-2021-44758 CVE-2022-3437 CVE-2022-41916 CVE-2022-42898 CVE-2022-44640 Debian Bug : 996586 Several vulnerabilities were discovered in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. CVE-2021-3671 Joseph Sutton discovered that the Heimdal KDC does not validate that the server name in the TGS-REQ is present before dereferencing, which may result in denial of service. CVE-2021-44758 It was discovered that Heimdal is prone to a NULL dereference in acceptors where an initial SPNEGO token that has no acceptable mechanisms, which may result in denial of service for a server application that uses SPNEGO. CVE-2022-3437 Several buffer overflow flaws and non-constant time leaks were discovered when using 1DES, 3DES or RC4 (arcfour). CVE-2022-41916 An out-of-bounds memory access was discovered when Heimdal normalizes Unicode, which may result in denial of service. CVE-2022-42898 It was discovered that integer overflows in PAC parsing may result in denial of service for Heimdal KDCs or possibly Heimdal servers. CVE-2022-44640 It was discovered that the Heimdal's ASN.1 compiler generates code that allows specially crafted DER encodings to invoke an invalid free on the decoded structure upon decode error, which may result in remote code execution in the Heimdal KDC. For the stable distribution (bullseye), theseproblems have been fixed in version 7.7.0+dfsg-2+deb11u2. We recommend that you upgrade your heimdal packages. For the detailed security status of heimdal please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/heimdal Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-5112-1 announces essential updates for OpenSSL to mitigate significant vulnerabilities and risks.. Debian Heimdal Update, Kerberos Security, Denial of Service Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 22, 2022 Critical Debian
89

Fedora 34: FEDORA-2021-f3d8515f03 Urgent: libcurl Memory Leak Issue

- CVE-2021-37750 (explicit NULL deref on KDC). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f2c8514f02 2021-08-27 18:55:25.463086 --------------------------------------------------------------------------------Name : krb5 Product : Fedora 33 Version : 1.18.2 Release : 31.fc33 URL : https://web.mit.edu/kerberos/www/ Summary : The Kerberos network authentication system Description : Kerberos V5 is a trusted-third-party network authentication system, which can improve your network's security by eliminating the insecure practice of sending passwords over the network in unencrypted form. --------------------------------------------------------------------------------Update Information: - CVE-2021-37750 (explicit NULL deref on KDC) --------------------------------------------------------------------------------ChangeLog: * Thu Aug 19 2021 Robbie Harwood - 1.18.2-31 - Fix KDC null deref on TGS inner body null server (CVE-2021-37750) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f2c8514f02' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Important notice regarding Fedora 33 concerning CVE-2021-37751 which pertains to a null pointer dereference vulnerability in krb5.. Fedora Security Update, Kerberos Authentication, KDC Vulnerability Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 27, 2021 Critical Fedora
87

Debian: DSA-4944-1 Critical: KDC Denial of Service Due to krb5

It was discovered that the Key Distribution Center (KDC) in krb5, the MIT implementation of Kerberos, is prone to a NULL pointer dereference flaw. An unauthenticated attacker can take advantage of this flaw to cause a denial of service (KDC crash) by sending a request containing a . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4944-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso July 25, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : krb5 CVE ID : CVE-2021-36222 Debian Bug : 991365 It was discovered that the Key Distribution Center (KDC) in krb5, the MIT implementation of Kerberos, is prone to a NULL pointer dereference flaw. An unauthenticated attacker can take advantage of this flaw to cause a denial of service (KDC crash) by sending a request containing a PA-ENCRYPTED-CHALLENGE padata element without using FAST. For the stable distribution (buster), this problem has been fixed in version 1.17-3+deb10u2. We recommend that you upgrade your krb5 packages. For the detailed security status of krb5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/krb5 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-5083-1 relates to a vulnerability in the KRB5 library, which could trigger service disruptions; users are urged to apply the fix and update their systems.. KDC Denial of Service, krb5 Update, Debian Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 25, 2021 Critical Debian
202

openSUSE 11.4: 2011:1169-1 Important: Kdc DoS and File Access

An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.. openSUSE Security Update: krb5: fixed kdc remote denial of service ( CVE-2011-1528, CVE-2011-1529) and unauthorized file access (CVE-2011-1526) ______________________________________________________________________________ Announcement ID: openSUSE-SU-2011:1169-1 Rating: important References: #719393 Cross-References: CVE-2011-1526 CVE-2011-1528 CVE-2011-1529 Affected Products: openSUSE 11.4 openSUSE 11.3 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: The following issues have been fixed: - CVE-2011-1528: In releases krb5-1.8 and later, the KDC can crash due to an assertion failure. - CVE-2011-1529: In releases krb5-1.8 and later, the KDC can crash due to a null pointer dereference. Both bugs could be triggered by unauthenticated remote attackers. Additionally CVE-2011-1526 was fixed that allowed authenticated users to access files via krb5 ftpd they should not have access to. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4: zypper in -t patch krb5-5303 - openSUSE 11.3: zypper in -t patch krb5-5303 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.4 (i586 x86_64): krb5-1.8.3-16.19.1 krb5-appl-clients-1.0-7.10.1 krb5-appl-servers-1.0-7.10.1 krb5-client-1.8.3-16.19.1 krb5-devel-1.8.3-16.19.1 krb5-plugin-kdb-ldap-1.8.3-16.19.1 krb5-plugin-preauth-pkinit-1.8.3-16.19.1 krb5-server-1.8.3-16.19.1 - openSUSE 11.4 (x86_64): krb5-32bit-1.8.3-16.19.1 krb5-devel-32bit-1.8.3-16.19.1 - openSUSE 11.3 (i586 x86_64): krb5-1.8.1-5.11.1 krb5-appl-clients-1.0-4.3.1 krb5-appl-servers-1.0-4.3.1 krb5-client-1.8.1-5.11.1 krb5-devel-1.8.1-5.11.1 krb5-plugin-kdb-ldap-1.8.1-5.11.1 krb5-plugin-preauth-pkinit-1.8.1-5.11.1 krb5-server-1.8.1-5.11.1 - openSUSE 11.3 (x86_64): krb5-32bit-1.8.1-5.11.1 krb5-devel-32bit-1.8.1-5.11.1 References: https://www.suse.com/security/cve/CVE-2011-1526.html https://www.suse.com/security/cve/CVE-2011-1528.html https://www.suse.com/security/cve/CVE-2011-1529.html . Key announcement regarding openSUSE krb5 to fix severe kdc service disruptions and prevent unauthorized access incidents.. openSUSE Security Update, krb5, denial of service, unauthorized access. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 24, 2011 Important OpenSUSE
172

Ubuntu 11.10 USN-1233-1 Critical: Kerberos Denial Of Service Issue

Several denial of service issues were fixed in the Kerberos KeyDistribution Center (KDC).. =========================================================================Ubuntu Security Notice USN-1233-1 October 18, 2011 krb5 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: Several denial of service issues were fixed in the Kerberos Key Distribution Center (KDC). Software Description: - krb5: MIT Kerberos Network Authentication Protocol Details: Nalin Dahyabhai, Andrej Ota and Kyle Moffett discovered a NULL pointer dereference in the KDC LDAP backend. An unauthenticated remote attacker could use this to cause a denial of service. This issue affected Ubuntu 11.10. (CVE-2011-1527) Mark Deneen discovered that an assert() could be triggered in the krb5_ldap_lockout_audit() function in the KDC LDAP backend and the krb5_db2_lockout_audit() function in the KDC DB2 backend. An unauthenticated remote attacker could use this to cause a denial of service. (CVE-2011-1528) It was discovered that a NULL pointer dereference could occur in the lookup_lockout_policy() function in the KDC LDAP and DB2 backends. An unauthenticated remote attacker could use this to cause a denial of service. (CVE-2011-1529) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: krb5-kdc 1.9.1+dfsg-1ubuntu1.1 krb5-kdc-ldap 1.9.1+dfsg-1ubuntu1.1 Ubuntu 11.04: krb5-kdc 1.8.3+dfsg-5ubuntu2.2 krb5-kdc-ldap 1.8.3+dfsg-5ubuntu2.2 Ubuntu 10.10: krb5-kdc 1.8.1+dfsg-5ubuntu0.8 krb5-kdc-ldap 1.8.1+dfsg-5ubuntu0.8 Ubuntu 10.04 LTS: krb5-kdc 1.8.1+dfsg-2ubuntu0.10 krb5-kdc-ldap 1.8.1+dfsg-2ubuntu0.10 In general, a standardsystem update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1233-1 CVE-2011-1527, CVE-2011-1528, CVE-2011-1529 Package Information: https://launchpad.net/ubuntu/+source/krb5/1.9.1+dfsg-1ubuntu1.1 https://launchpad.net/ubuntu/+source/krb5/1.8.3+dfsg-5ubuntu2.2 https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-5ubuntu0.8 https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.10 . Multiple denial of service vulnerabilities resolved in Kerberos KDC, impacting Ubuntu 10.04 LTS and newer releases. Upgrade promptly.. Denial Of Service, Kerberos KDC, Ubuntu Update, Security Patch, Remote Attack. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 18, 2011 Critical Ubuntu
172

Ubuntu 10.04 LTS: USN-999-1 Addresses Moderate KDC DoS Vulnerability

Mike Roszkowski discovered that the Kerberos KDC did not correctlyvalidate the contents of certain messages. If an authenticated remoteattacker sent specially crafted TGS requests, the KDC service would crash,leading to a denial of service. [More...]. ==========================================================Ubuntu Security Notice USN-999-1 October 05, 2010 krb5 vulnerability CVE-2010-1322 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 10.04 LTS Ubuntu 10.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 10.04 LTS: krb5-kdc 1.8.1+dfsg-2ubuntu0.3 Ubuntu 10.10: krb5-kdc 1.8.1+dfsg-5ubuntu0.1 In general, a standard system update will make all the necessary changes. Details follow: Mike Roszkowski discovered that the Kerberos KDC did not correctly validate the contents of certain messages. If an authenticated remote attacker sent specially crafted TGS requests, the KDC service would crash, leading to a denial of service. Updated packages for Ubuntu 10.04 LTS: Source archives: Size/MD5: 124007 e89b14cbc851f911f5ead11f9bd92f9a Size/MD5: 1721 b9e6cecfacd4cd487094eeec0e657953 Size/MD5: 11649920 6f65349b14dcaf862805ff98bfcbd4f8 Architecture independent packages: Size/MD5: 2249062 113ee25d58f8dc482476fe05eb213156 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 104192 ad3b52e518bb5ebc1dd8fd28c75dbb52 Size/MD5: 137486 01b07345094e2cd710dec001f8d7a9f2 Size/MD5: 128468 f073edbfb20a8749b5a4a17ce62bf935 Size/MD5: 81808 70f7ff9383b1a300beed6b4b909e9d83 Size/MD5: 104170 0ae08cfffa3b34b004e7ca1021886c5f Size/MD5: 62938 51eb9af659cc9781701de5fbc2df4559 Size/MD5: 76420ed09af29a5b1dd06ec8f5ddf6bc93e73 Size/MD5: 62272 0a0dad569ec982e349909466ab9a0276 Size/MD5: 368488 1b2fa04c5f6c62538e2665eeebf39afd Size/MD5: 1625886 6fcb8f2e39a798bb5b468522bf027955 Size/MD5: 35912 de1b46f9e84e4e890a1c8a44c9785b3e Size/MD5: 44926 a24f9a0002ded4e913dc0e49c28ae567 Size/MD5: 112056 80dd4f2851091f5d0e8ad0606fd55743 Size/MD5: 116220 10a7ec8508baa0c4f6551d449009042d Size/MD5: 217652 598ce5cb5adf5c4764c9dbf18f625622 Size/MD5: 76610 ec6aa6791892111b539cdc35f704152c i386 architecture (x86 compatible Intel/AMD): Size/MD5: 102502 a0f3f2aba06beaa76af146dc0e7852f5 Size/MD5: 127694 0cb599cecf0398401655527f86c5a1af Size/MD5: 120474 f5f496ab58743d6d43a77680cc97a4ba Size/MD5: 75124 add9e17c477a487ea52579eef82032f2 Size/MD5: 96320 5bf4eb62eed1c2e4a4c59421ba84c3b7 Size/MD5: 58858 404524fc4e758202d4b43a40a71902c7 Size/MD5: 71826 552efa91ee75157790df8906c0660644 Size/MD5: 58972 6048dfcc7dc948031ba8b964b7e1dbea Size/MD5: 350170 d47b1e8c6f135b93ebcf28eeaedafb90 Size/MD5: 1607490 11857ab8b8f32e6847b28d18dc3a1979 Size/MD5: 35914 cade0c1ebeaa321f09d9700c7d251cf7 Size/MD5: 42398 2cd4f7ca95d280108858cbc51d1b2c3e Size/MD5: 104978 33fbcee864d3932291761294385f2676 Size/MD5: 110720 3ff3d34826fbf64d0d833ee4546c9be8 Size/MD5: 201618 0776a15b98cd2471eedda756fc01bf5f Size/MD5: 73562 7910cc8f6eae4a2b64d6074dbcd45e4d powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 102518 b1720558b95d2dc7bb86b0c2b470816b Size/MD5: 134080 fe11f236780948e9f000090b749cd157 Size/MD5: 126530 ebf3c7e86b76cc11e8eb09c83154107b Size/MD5: 80558 69dba3bc6b015a7fc502fd10ac0a90d6 Size/MD5: 110770 e128cf8eba67fade6c95ede9dd106018 Size/MD5: 607880a06ffec964e1ce2471185cc82cce4c4 Size/MD5: 75492 1bcc38b8eaa84820e6fd5604390f5c0c Size/MD5: 61140 241721eb6595c49790dac92fde220c28 Size/MD5: 372698 aa09f2e0845e626bdbcb905285eabe81 Size/MD5: 1674170 0aa7146a17968c1011dcdaa3b4e20779 Size/MD5: 35932 81e71dd0310d48b756809c6225b8434e Size/MD5: 43704 a89476cd927987c50fc8e9d1a3c1be7e Size/MD5: 110666 0b6122e99dc0c9136b8f507715a4e866 Size/MD5: 116312 df3c876c6719fe9ed382deb7b6c97586 Size/MD5: 214998 d8efc09e8c0d4925b77c3270f625b258 Size/MD5: 74668 c171c8f7fe8054f7f7fae79690dd9149 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 102526 7524e965535daf84c8e8da012fde6bc9 Size/MD5: 131862 28f41f0288b0e3cdd99eae78a3e61612 Size/MD5: 114792 0b4e549e29d879ddb2bff59075df7157 Size/MD5: 75968 de3e951cd7ded25365ed87ebe15fef77 Size/MD5: 109186 b6dbac59f1c557496607e0c3fe075b5c Size/MD5: 58024 15f191df943892f3c8ff3fb5ecfc9132 Size/MD5: 70190 1eb1359f028fe5f19b07fac920ea3e95 Size/MD5: 57758 b75d3fcdb4e2d223d2688a8addd26388 Size/MD5: 342002 ac22b1ec984b67dc64f07b8e7d8f23b1 Size/MD5: 1519716 253207bf983e70db6abf36c45684519b Size/MD5: 35936 8153af761a217b1ced0ffa7247417cfb Size/MD5: 42454 14e3f9e84d127bf9385156c785c31144 Size/MD5: 108084 1b1a232f61bfee5973ecb591595e68a4 Size/MD5: 111542 89815a95c663ac519e1a1016417275a1 Size/MD5: 205808 75665681a6be2a990b3fa3875fa9d92c Size/MD5: 69452 f0aa40800d5a59b778d65cc795935c2f Updated packages for Ubuntu 10.10: Source archives: Size/MD5: 125889 4d36b484d414568ec5566217a4905a04 Size/MD5: 1726 7508245469643220515393012e98320d Size/MD5: 11649920 6f65349b14dcaf862805ff98bfcbd4f8 Architecture independent packages: Size/MD5: 2249140 f29b74548048cca53b27a6648a5e7317 amd64architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 102580 a286d40bdd016169f77da3a0fe8c6595 Size/MD5: 135506 be88b076ba9382310026e573b32feac1 Size/MD5: 127880 39489cee58717bf9c8c37f7bdec946dd Size/MD5: 81260 9c733722e50181a157d7620356ba6202 Size/MD5: 103668 28ba461fe0af19812a33b646a02cd85b Size/MD5: 61872 aa139b218eb774df1458b34c76269eca Size/MD5: 75642 a03133c019caba1fb9366c93d7edf9ca Size/MD5: 61452 c85c1311d1abc41ca3d3d219cfce7c04 Size/MD5: 367060 dde10b588682e00d0011f32eabe9fba2 Size/MD5: 1631962 4f05ff95367b927a30b6006f7fed6265 Size/MD5: 36020 f6919e82b4c58fb00d8cc66d4c9f7646 Size/MD5: 44076 bc959964be0108123dd3fe6c246981eb Size/MD5: 112104 627d5c1760959c77d2460a992be519a4 Size/MD5: 116162 74fe563d4d1f7d020c820a7d2e858c82 Size/MD5: 216678 aecec368508031a27c71eec0fea029c0 Size/MD5: 76020 fa46f6f5fa91c203e9c3865c97b73750 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 102570 2ad73e540e951dc1a5af042677061094 Size/MD5: 126532 e13c30c0537e4775fbd85753cd7db6d9 Size/MD5: 119800 ddf0a9e5e5012e2db6d368d5aeb6aa30 Size/MD5: 74614 e604bf1959ebd6154245e41f996b4cd1 Size/MD5: 95866 c1517ce2a1a5e8d10bfe622c99ae82e2 Size/MD5: 58504 184f588d89a11d190733fd2c1ab2fc54 Size/MD5: 71204 b0501bdce35869fe4c00633b3b48679e Size/MD5: 58630 880c9d051e03aaa47f3688687cf1948e Size/MD5: 348112 6b80a54943f102d2eb99e34d5e8598d4 Size/MD5: 1612676 681405ac6c28dd632ac2c53115870f79 Size/MD5: 36018 f6f1b515390b49728020dcb3d49d5dd8 Size/MD5: 42234 19918f3bb9d3bc2ea772f662629aaaa0 Size/MD5: 104178 83c0c0d1b3a1bbe75ee523cf40d5bb27 Size/MD5: 110372 c6bbd5e9a030d316647e0de24b11678c Size/MD5: 200076 ec20c44268ed19bd8af04280ee175a8c Size/MD5: 72684f1e607965bd5c01bcc75f132766bd038 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 102582 e674ffaab23aa4c2885b027212d5c05b Size/MD5: 132760 cf5dd85bba5698df4cb0dbe51b2ef3ee Size/MD5: 125700 b7844693179f983945614299bce895b3 Size/MD5: 80130 dd180b81df325da8c15744275c0646bd Size/MD5: 108246 78ee1ea83218b3f080153f12fbc1d249 Size/MD5: 60328 8b63ba2d59adb0f2a30d51c5af634a4b Size/MD5: 74752 4752365abded8723621d941399c8b475 Size/MD5: 60716 57a6cf0f20c1271234841940bcb3e062 Size/MD5: 370868 3b2b049889cb9ce91456ecb2c7b2dcf3 Size/MD5: 1680272 a6b23e08d08a80d62fd2d7ce2ba44e89 Size/MD5: 36022 cb7842211807fc0bccbaabae802d4246 Size/MD5: 43520 dc3e241cd0af9fc2bd7b76158b19649f Size/MD5: 109766 438e0857de5f1f7840937bdeb0688f22 Size/MD5: 115708 99a31337836e7f98f88512c5a83e534a Size/MD5: 213386 987b5a28fbd13b4133c1341d59e7c614 Size/MD5: 74048 72fbb5274e7393609d98df0b0ab0dc61 . ==========================================================Ubuntu Security Notice USN-999-1 October 0. roszkowski, kerberos, correctlyvalidate, contents, certain. . LinuxSecurity.com Team

Calendar%202 Oct 05, 2010 Ubuntu
98

Red Hat Enterprise Linux RHSA-2010:0029-01 Critical: KDC DoS Threat

Updated krb5 packages that fix multiple security issues are now available for Red Hat Enterprise Linux 3, 4, and 5, and Red Hat Enterprise Linux 4.7, 5.2, and 5.3 Extended Update Support. This update has been rated as having critical security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Critical: krb5 security update Advisory ID: RHSA-2010:0029-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2010:0029.html Issue date: 2010-01-12 CVE Names: CVE-2009-4212 ==================================================================== 1. Summary: Updated krb5 packages that fix multiple security issues are now available for Red Hat Enterprise Linux 3, 4, and 5, and Red Hat Enterprise Linux 4.7, 5.2, and 5.3 Extended Update Support. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux (v. 5.2.z server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux (v. 5.3.z server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux AS version 4.7.z - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux ES version 4.7.z - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386,ia64, x86_64 3. Description: Kerberos is a network authentication system which allows clients and servers to authenticate to each other using symmetric encryption and a trusted third party, the Key Distribution Center (KDC). Multiple integer underflow flaws, leading to heap-based corruption, were found in the way the MIT Kerberos Key Distribution Center (KDC) decrypted ciphertexts encrypted with the Advanced Encryption Standard (AES) and ARCFOUR (RC4) encryption algorithms. If a remote KDC client were able to provide a specially-crafted AES- or RC4-encrypted ciphertext or texts, it could potentially lead to either a denial of service of the central KDC (KDC crash or abort upon processing the crafted ciphertext), or arbitrary code execution with the privileges of the KDC (i.e., root privileges). (CVE-2009-4212) All krb5 users should upgrade to these updated packages, which contain a backported patch to correct these issues. All running services using the MIT Kerberos libraries must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 545015 - CVE-2009-4212 krb: KDC integer overflows in AES and RC4 decryption routines (MITKRB5-SA-2009-004) 6. Package List: Red Hat Enterprise Linux AS version3: Source: i386: krb5-debuginfo-1.2.7-71.i386.rpm krb5-devel-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.i386.rpm krb5-server-1.2.7-71.i386.rpm krb5-workstation-1.2.7-71.i386.rpm ia64: krb5-debuginfo-1.2.7-71.i386.rpm krb5-debuginfo-1.2.7-71.ia64.rpm krb5-devel-1.2.7-71.ia64.rpm krb5-libs-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.ia64.rpm krb5-server-1.2.7-71.ia64.rpm krb5-workstation-1.2.7-71.ia64.rpm ppc: krb5-debuginfo-1.2.7-71.ppc.rpm krb5-debuginfo-1.2.7-71.ppc64.rpm krb5-devel-1.2.7-71.ppc.rpm krb5-libs-1.2.7-71.ppc.rpm krb5-libs-1.2.7-71.ppc64.rpm krb5-server-1.2.7-71.ppc.rpm krb5-workstation-1.2.7-71.ppc.rpm s390: krb5-debuginfo-1.2.7-71.s390.rpm krb5-devel-1.2.7-71.s390.rpm krb5-libs-1.2.7-71.s390.rpm krb5-server-1.2.7-71.s390.rpm krb5-workstation-1.2.7-71.s390.rpm s390x: krb5-debuginfo-1.2.7-71.s390.rpm krb5-debuginfo-1.2.7-71.s390x.rpm krb5-devel-1.2.7-71.s390x.rpm krb5-libs-1.2.7-71.s390.rpm krb5-libs-1.2.7-71.s390x.rpm krb5-server-1.2.7-71.s390x.rpm krb5-workstation-1.2.7-71.s390x.rpm x86_64: krb5-debuginfo-1.2.7-71.i386.rpm krb5-debuginfo-1.2.7-71.x86_64.rpm krb5-devel-1.2.7-71.x86_64.rpm krb5-libs-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.x86_64.rpm krb5-server-1.2.7-71.x86_64.rpm krb5-workstation-1.2.7-71.x86_64.rpm Red Hat Desktop version 3: Source: i386: krb5-debuginfo-1.2.7-71.i386.rpm krb5-devel-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.i386.rpm krb5-server-1.2.7-71.i386.rpm krb5-workstation-1.2.7-71.i386.rpm x86_64: krb5-debuginfo-1.2.7-71.i386.rpm krb5-debuginfo-1.2.7-71.x86_64.rpm krb5-devel-1.2.7-71.x86_64.rpm krb5-libs-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.x86_64.rpm krb5-server-1.2.7-71.x86_64.rpm krb5-workstation-1.2.7-71.x86_64.rpm Red Hat Enterprise Linux ES version3: Source: i386: krb5-debuginfo-1.2.7-71.i386.rpm krb5-devel-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.i386.rpm krb5-server-1.2.7-71.i386.rpm krb5-workstation-1.2.7-71.i386.rpm ia64: krb5-debuginfo-1.2.7-71.i386.rpm krb5-debuginfo-1.2.7-71.ia64.rpm krb5-devel-1.2.7-71.ia64.rpm krb5-libs-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.ia64.rpm krb5-server-1.2.7-71.ia64.rpm krb5-workstation-1.2.7-71.ia64.rpm x86_64: krb5-debuginfo-1.2.7-71.i386.rpm krb5-debuginfo-1.2.7-71.x86_64.rpm krb5-devel-1.2.7-71.x86_64.rpm krb5-libs-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.x86_64.rpm krb5-server-1.2.7-71.x86_64.rpm krb5-workstation-1.2.7-71.x86_64.rpm Red Hat Enterprise Linux WS version 3: Source: i386: krb5-debuginfo-1.2.7-71.i386.rpm krb5-devel-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.i386.rpm krb5-server-1.2.7-71.i386.rpm krb5-workstation-1.2.7-71.i386.rpm ia64: krb5-debuginfo-1.2.7-71.i386.rpm krb5-debuginfo-1.2.7-71.ia64.rpm krb5-devel-1.2.7-71.ia64.rpm krb5-libs-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.ia64.rpm krb5-server-1.2.7-71.ia64.rpm krb5-workstation-1.2.7-71.ia64.rpm x86_64: krb5-debuginfo-1.2.7-71.i386.rpm krb5-debuginfo-1.2.7-71.x86_64.rpm krb5-devel-1.2.7-71.x86_64.rpm krb5-libs-1.2.7-71.i386.rpm krb5-libs-1.2.7-71.x86_64.rpm krb5-server-1.2.7-71.x86_64.rpm krb5-workstation-1.2.7-71.x86_64.rpm Red Hat Enterprise Linux AS version4: Source: i386: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-devel-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-server-1.3.4-62.el4_8.1.i386.rpm krb5-workstation-1.3.4-62.el4_8.1.i386.rpm ia64: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-debuginfo-1.3.4-62.el4_8.1.ia64.rpm krb5-devel-1.3.4-62.el4_8.1.ia64.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.ia64.rpm krb5-server-1.3.4-62.el4_8.1.ia64.rpm krb5-workstation-1.3.4-62.el4_8.1.ia64.rpm ppc: krb5-debuginfo-1.3.4-62.el4_8.1.ppc.rpm krb5-debuginfo-1.3.4-62.el4_8.1.ppc64.rpm krb5-devel-1.3.4-62.el4_8.1.ppc.rpm krb5-libs-1.3.4-62.el4_8.1.ppc.rpm krb5-libs-1.3.4-62.el4_8.1.ppc64.rpm krb5-server-1.3.4-62.el4_8.1.ppc.rpm krb5-workstation-1.3.4-62.el4_8.1.ppc.rpm s390: krb5-debuginfo-1.3.4-62.el4_8.1.s390.rpm krb5-devel-1.3.4-62.el4_8.1.s390.rpm krb5-libs-1.3.4-62.el4_8.1.s390.rpm krb5-server-1.3.4-62.el4_8.1.s390.rpm krb5-workstation-1.3.4-62.el4_8.1.s390.rpm s390x: krb5-debuginfo-1.3.4-62.el4_8.1.s390.rpm krb5-debuginfo-1.3.4-62.el4_8.1.s390x.rpm krb5-devel-1.3.4-62.el4_8.1.s390x.rpm krb5-libs-1.3.4-62.el4_8.1.s390.rpm krb5-libs-1.3.4-62.el4_8.1.s390x.rpm krb5-server-1.3.4-62.el4_8.1.s390x.rpm krb5-workstation-1.3.4-62.el4_8.1.s390x.rpm x86_64: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-debuginfo-1.3.4-62.el4_8.1.x86_64.rpm krb5-devel-1.3.4-62.el4_8.1.x86_64.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.x86_64.rpm krb5-server-1.3.4-62.el4_8.1.x86_64.rpm krb5-workstation-1.3.4-62.el4_8.1.x86_64.rpm Red Hat Enterprise Linux AS version4.7.z: Source: krb5-1.3.4-60.el4_7.3.src.rpm i386: krb5-debuginfo-1.3.4-60.el4_7.3.i386.rpm krb5-devel-1.3.4-60.el4_7.3.i386.rpm krb5-libs-1.3.4-60.el4_7.3.i386.rpm krb5-server-1.3.4-60.el4_7.3.i386.rpm krb5-workstation-1.3.4-60.el4_7.3.i386.rpm ia64: krb5-debuginfo-1.3.4-60.el4_7.3.i386.rpm krb5-debuginfo-1.3.4-60.el4_7.3.ia64.rpm krb5-devel-1.3.4-60.el4_7.3.ia64.rpm krb5-libs-1.3.4-60.el4_7.3.i386.rpm krb5-libs-1.3.4-60.el4_7.3.ia64.rpm krb5-server-1.3.4-60.el4_7.3.ia64.rpm krb5-workstation-1.3.4-60.el4_7.3.ia64.rpm ppc: krb5-debuginfo-1.3.4-60.el4_7.3.ppc.rpm krb5-debuginfo-1.3.4-60.el4_7.3.ppc64.rpm krb5-devel-1.3.4-60.el4_7.3.ppc.rpm krb5-libs-1.3.4-60.el4_7.3.ppc.rpm krb5-libs-1.3.4-60.el4_7.3.ppc64.rpm krb5-server-1.3.4-60.el4_7.3.ppc.rpm krb5-workstation-1.3.4-60.el4_7.3.ppc.rpm s390: krb5-debuginfo-1.3.4-60.el4_7.3.s390.rpm krb5-devel-1.3.4-60.el4_7.3.s390.rpm krb5-libs-1.3.4-60.el4_7.3.s390.rpm krb5-server-1.3.4-60.el4_7.3.s390.rpm krb5-workstation-1.3.4-60.el4_7.3.s390.rpm s390x: krb5-debuginfo-1.3.4-60.el4_7.3.s390.rpm krb5-debuginfo-1.3.4-60.el4_7.3.s390x.rpm krb5-devel-1.3.4-60.el4_7.3.s390x.rpm krb5-libs-1.3.4-60.el4_7.3.s390.rpm krb5-libs-1.3.4-60.el4_7.3.s390x.rpm krb5-server-1.3.4-60.el4_7.3.s390x.rpm krb5-workstation-1.3.4-60.el4_7.3.s390x.rpm x86_64: krb5-debuginfo-1.3.4-60.el4_7.3.i386.rpm krb5-debuginfo-1.3.4-60.el4_7.3.x86_64.rpm krb5-devel-1.3.4-60.el4_7.3.x86_64.rpm krb5-libs-1.3.4-60.el4_7.3.i386.rpm krb5-libs-1.3.4-60.el4_7.3.x86_64.rpm krb5-server-1.3.4-60.el4_7.3.x86_64.rpm krb5-workstation-1.3.4-60.el4_7.3.x86_64.rpm Red Hat Enterprise Linux Desktop version4: Source: i386: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-devel-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-server-1.3.4-62.el4_8.1.i386.rpm krb5-workstation-1.3.4-62.el4_8.1.i386.rpm x86_64: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-debuginfo-1.3.4-62.el4_8.1.x86_64.rpm krb5-devel-1.3.4-62.el4_8.1.x86_64.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.x86_64.rpm krb5-server-1.3.4-62.el4_8.1.x86_64.rpm krb5-workstation-1.3.4-62.el4_8.1.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-devel-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-server-1.3.4-62.el4_8.1.i386.rpm krb5-workstation-1.3.4-62.el4_8.1.i386.rpm ia64: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-debuginfo-1.3.4-62.el4_8.1.ia64.rpm krb5-devel-1.3.4-62.el4_8.1.ia64.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.ia64.rpm krb5-server-1.3.4-62.el4_8.1.ia64.rpm krb5-workstation-1.3.4-62.el4_8.1.ia64.rpm x86_64: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-debuginfo-1.3.4-62.el4_8.1.x86_64.rpm krb5-devel-1.3.4-62.el4_8.1.x86_64.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.x86_64.rpm krb5-server-1.3.4-62.el4_8.1.x86_64.rpm krb5-workstation-1.3.4-62.el4_8.1.x86_64.rpm Red Hat Enterprise Linux ES version4.7.z: Source: krb5-1.3.4-60.el4_7.3.src.rpm i386: krb5-debuginfo-1.3.4-60.el4_7.3.i386.rpm krb5-devel-1.3.4-60.el4_7.3.i386.rpm krb5-libs-1.3.4-60.el4_7.3.i386.rpm krb5-server-1.3.4-60.el4_7.3.i386.rpm krb5-workstation-1.3.4-60.el4_7.3.i386.rpm ia64: krb5-debuginfo-1.3.4-60.el4_7.3.i386.rpm krb5-debuginfo-1.3.4-60.el4_7.3.ia64.rpm krb5-devel-1.3.4-60.el4_7.3.ia64.rpm krb5-libs-1.3.4-60.el4_7.3.i386.rpm krb5-libs-1.3.4-60.el4_7.3.ia64.rpm krb5-server-1.3.4-60.el4_7.3.ia64.rpm krb5-workstation-1.3.4-60.el4_7.3.ia64.rpm x86_64: krb5-debuginfo-1.3.4-60.el4_7.3.i386.rpm krb5-debuginfo-1.3.4-60.el4_7.3.x86_64.rpm krb5-devel-1.3.4-60.el4_7.3.x86_64.rpm krb5-libs-1.3.4-60.el4_7.3.i386.rpm krb5-libs-1.3.4-60.el4_7.3.x86_64.rpm krb5-server-1.3.4-60.el4_7.3.x86_64.rpm krb5-workstation-1.3.4-60.el4_7.3.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-devel-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-server-1.3.4-62.el4_8.1.i386.rpm krb5-workstation-1.3.4-62.el4_8.1.i386.rpm ia64: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-debuginfo-1.3.4-62.el4_8.1.ia64.rpm krb5-devel-1.3.4-62.el4_8.1.ia64.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.ia64.rpm krb5-server-1.3.4-62.el4_8.1.ia64.rpm krb5-workstation-1.3.4-62.el4_8.1.ia64.rpm x86_64: krb5-debuginfo-1.3.4-62.el4_8.1.i386.rpm krb5-debuginfo-1.3.4-62.el4_8.1.x86_64.rpm krb5-devel-1.3.4-62.el4_8.1.x86_64.rpm krb5-libs-1.3.4-62.el4_8.1.i386.rpm krb5-libs-1.3.4-62.el4_8.1.x86_64.rpm krb5-server-1.3.4-62.el4_8.1.x86_64.rpm krb5-workstation-1.3.4-62.el4_8.1.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: krb5-debuginfo-1.6.1-36.el5_4.1.i386.rpm krb5-libs-1.6.1-36.el5_4.1.i386.rpm krb5-workstation-1.6.1-36.el5_4.1.i386.rpm x86_64: krb5-debuginfo-1.6.1-36.el5_4.1.i386.rpm krb5-debuginfo-1.6.1-36.el5_4.1.x86_64.rpm krb5-libs-1.6.1-36.el5_4.1.i386.rpm krb5-libs-1.6.1-36.el5_4.1.x86_64.rpm krb5-workstation-1.6.1-36.el5_4.1.x86_64.rpm RHELDesktop Workstation (v. 5 client): Source: i386: krb5-debuginfo-1.6.1-36.el5_4.1.i386.rpm krb5-devel-1.6.1-36.el5_4.1.i386.rpm krb5-server-1.6.1-36.el5_4.1.i386.rpm x86_64: krb5-debuginfo-1.6.1-36.el5_4.1.i386.rpm krb5-debuginfo-1.6.1-36.el5_4.1.x86_64.rpm krb5-devel-1.6.1-36.el5_4.1.i386.rpm krb5-devel-1.6.1-36.el5_4.1.x86_64.rpm krb5-server-1.6.1-36.el5_4.1.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): Source: i386: krb5-debuginfo-1.6.1-36.el5_4.1.i386.rpm krb5-devel-1.6.1-36.el5_4.1.i386.rpm krb5-libs-1.6.1-36.el5_4.1.i386.rpm krb5-server-1.6.1-36.el5_4.1.i386.rpm krb5-workstation-1.6.1-36.el5_4.1.i386.rpm ia64: krb5-debuginfo-1.6.1-36.el5_4.1.i386.rpm krb5-debuginfo-1.6.1-36.el5_4.1.ia64.rpm krb5-devel-1.6.1-36.el5_4.1.ia64.rpm krb5-libs-1.6.1-36.el5_4.1.i386.rpm krb5-libs-1.6.1-36.el5_4.1.ia64.rpm krb5-server-1.6.1-36.el5_4.1.ia64.rpm krb5-workstation-1.6.1-36.el5_4.1.ia64.rpm ppc: krb5-debuginfo-1.6.1-36.el5_4.1.ppc.rpm krb5-debuginfo-1.6.1-36.el5_4.1.ppc64.rpm krb5-devel-1.6.1-36.el5_4.1.ppc.rpm krb5-devel-1.6.1-36.el5_4.1.ppc64.rpm krb5-libs-1.6.1-36.el5_4.1.ppc.rpm krb5-libs-1.6.1-36.el5_4.1.ppc64.rpm krb5-server-1.6.1-36.el5_4.1.ppc.rpm krb5-workstation-1.6.1-36.el5_4.1.ppc.rpm s390x: krb5-debuginfo-1.6.1-36.el5_4.1.s390.rpm krb5-debuginfo-1.6.1-36.el5_4.1.s390x.rpm krb5-devel-1.6.1-36.el5_4.1.s390.rpm krb5-devel-1.6.1-36.el5_4.1.s390x.rpm krb5-libs-1.6.1-36.el5_4.1.s390.rpm krb5-libs-1.6.1-36.el5_4.1.s390x.rpm krb5-server-1.6.1-36.el5_4.1.s390x.rpm krb5-workstation-1.6.1-36.el5_4.1.s390x.rpm x86_64: krb5-debuginfo-1.6.1-36.el5_4.1.i386.rpm krb5-debuginfo-1.6.1-36.el5_4.1.x86_64.rpm krb5-devel-1.6.1-36.el5_4.1.i386.rpm krb5-devel-1.6.1-36.el5_4.1.x86_64.rpm krb5-libs-1.6.1-36.el5_4.1.i386.rpm krb5-libs-1.6.1-36.el5_4.1.x86_64.rpm krb5-server-1.6.1-36.el5_4.1.x86_64.rpm krb5-workstation-1.6.1-36.el5_4.1.x86_64.rpm Red Hat Enterprise Linux (v. 5.2.zserver): Source: krb5-1.6.1-25.el5_2.3.src.rpm i386: krb5-debuginfo-1.6.1-25.el5_2.3.i386.rpm krb5-devel-1.6.1-25.el5_2.3.i386.rpm krb5-libs-1.6.1-25.el5_2.3.i386.rpm krb5-server-1.6.1-25.el5_2.3.i386.rpm krb5-workstation-1.6.1-25.el5_2.3.i386.rpm ia64: krb5-debuginfo-1.6.1-25.el5_2.3.i386.rpm krb5-debuginfo-1.6.1-25.el5_2.3.ia64.rpm krb5-devel-1.6.1-25.el5_2.3.ia64.rpm krb5-libs-1.6.1-25.el5_2.3.i386.rpm krb5-libs-1.6.1-25.el5_2.3.ia64.rpm krb5-server-1.6.1-25.el5_2.3.ia64.rpm krb5-workstation-1.6.1-25.el5_2.3.ia64.rpm ppc: krb5-debuginfo-1.6.1-25.el5_2.3.ppc.rpm krb5-debuginfo-1.6.1-25.el5_2.3.ppc64.rpm krb5-devel-1.6.1-25.el5_2.3.ppc.rpm krb5-devel-1.6.1-25.el5_2.3.ppc64.rpm krb5-libs-1.6.1-25.el5_2.3.ppc.rpm krb5-libs-1.6.1-25.el5_2.3.ppc64.rpm krb5-server-1.6.1-25.el5_2.3.ppc.rpm krb5-workstation-1.6.1-25.el5_2.3.ppc.rpm s390x: krb5-debuginfo-1.6.1-25.el5_2.3.s390.rpm krb5-debuginfo-1.6.1-25.el5_2.3.s390x.rpm krb5-devel-1.6.1-25.el5_2.3.s390.rpm krb5-devel-1.6.1-25.el5_2.3.s390x.rpm krb5-libs-1.6.1-25.el5_2.3.s390.rpm krb5-libs-1.6.1-25.el5_2.3.s390x.rpm krb5-server-1.6.1-25.el5_2.3.s390x.rpm krb5-workstation-1.6.1-25.el5_2.3.s390x.rpm x86_64: krb5-debuginfo-1.6.1-25.el5_2.3.i386.rpm krb5-debuginfo-1.6.1-25.el5_2.3.x86_64.rpm krb5-devel-1.6.1-25.el5_2.3.i386.rpm krb5-devel-1.6.1-25.el5_2.3.x86_64.rpm krb5-libs-1.6.1-25.el5_2.3.i386.rpm krb5-libs-1.6.1-25.el5_2.3.x86_64.rpm krb5-server-1.6.1-25.el5_2.3.x86_64.rpm krb5-workstation-1.6.1-25.el5_2.3.x86_64.rpm Red Hat Enterprise Linux (v. 5.3.zserver): Source: krb5-1.6.1-31.el5_3.4.src.rpm i386: krb5-debuginfo-1.6.1-31.el5_3.4.i386.rpm krb5-devel-1.6.1-31.el5_3.4.i386.rpm krb5-libs-1.6.1-31.el5_3.4.i386.rpm krb5-server-1.6.1-31.el5_3.4.i386.rpm krb5-workstation-1.6.1-31.el5_3.4.i386.rpm ia64: krb5-debuginfo-1.6.1-31.el5_3.4.i386.rpm krb5-debuginfo-1.6.1-31.el5_3.4.ia64.rpm krb5-devel-1.6.1-31.el5_3.4.ia64.rpm krb5-libs-1.6.1-31.el5_3.4.i386.rpm krb5-libs-1.6.1-31.el5_3.4.ia64.rpm krb5-server-1.6.1-31.el5_3.4.ia64.rpm krb5-workstation-1.6.1-31.el5_3.4.ia64.rpm ppc: krb5-debuginfo-1.6.1-31.el5_3.4.ppc.rpm krb5-debuginfo-1.6.1-31.el5_3.4.ppc64.rpm krb5-devel-1.6.1-31.el5_3.4.ppc.rpm krb5-devel-1.6.1-31.el5_3.4.ppc64.rpm krb5-libs-1.6.1-31.el5_3.4.ppc.rpm krb5-libs-1.6.1-31.el5_3.4.ppc64.rpm krb5-server-1.6.1-31.el5_3.4.ppc.rpm krb5-workstation-1.6.1-31.el5_3.4.ppc.rpm s390x: krb5-debuginfo-1.6.1-31.el5_3.4.s390.rpm krb5-debuginfo-1.6.1-31.el5_3.4.s390x.rpm krb5-devel-1.6.1-31.el5_3.4.s390.rpm krb5-devel-1.6.1-31.el5_3.4.s390x.rpm krb5-libs-1.6.1-31.el5_3.4.s390.rpm krb5-libs-1.6.1-31.el5_3.4.s390x.rpm krb5-server-1.6.1-31.el5_3.4.s390x.rpm krb5-workstation-1.6.1-31.el5_3.4.s390x.rpm x86_64: krb5-debuginfo-1.6.1-31.el5_3.4.i386.rpm krb5-debuginfo-1.6.1-31.el5_3.4.x86_64.rpm krb5-devel-1.6.1-31.el5_3.4.i386.rpm krb5-devel-1.6.1-31.el5_3.4.x86_64.rpm krb5-libs-1.6.1-31.el5_3.4.i386.rpm krb5-libs-1.6.1-31.el5_3.4.x86_64.rpm krb5-server-1.6.1-31.el5_3.4.x86_64.rpm krb5-workstation-1.6.1-31.el5_3.4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2009-4212 https://access.redhat.com/security/updates/classification#critical http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-004.txt 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2010 Red Hat, Inc. . Essential patchfor Red Hat Enterprise Linux addressing various vulnerabilities in krb5 to avert serious risks.. Red Hat Enterprise Linux, Kerberos Update, KDC Security, Critical Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 12, 2010 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200