Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
98

Red Hat Linux 9: RHSA-2003:091-01 Critical: Kerberos Authentication Attack

Updated Kerberos packages for Red Hat Linux 9 fix a number of vulnerabilities found in MIT Kerberos. . ` --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated kerberos packages fix various vulnerabilities Advisory ID: RHSA-2003:091-01 Issue date: 2003-04-02 Updated on: 2003-04-02 Product: Red Hat Linux Keywords: krb5 Cross references: RHSA-2003:051 RHSA-2003:052 Obsoletes: RHSA-2003:021 CVE Names: CAN-2003-0028 CAN-2003-082 CAN-2003-0138 CAN-2003-0139 ---------------------------------------------------------------------1. Topic: Updated Kerberos packages for Red Hat Linux 9 fix a number of vulnerabilities found in MIT Kerberos. 2. Relevant releases/architectures: Red Hat Linux 9 - i386 3. Problem description: Kerberos is a network authentication system. The MIT Kerberos team released an advisory describing a number of vulnerabilities that affect the kerberos packages shipped as part of Red Hat Linux 9. These issues include: Vulnerabilities have been found in the triple-DES key support found in the implementation of the Kerberos IV authentication protocol included in MIT Kerberos. The Common Vulnerabilities and Exposures project has assigned the name CAN-2003-0139 to this issue. Vulnerabilities have been found in the Kerberos IV authentication protocol which allow an attacker with knowledge of a cross-realm key, which is shared with another realm, to impersonate any principal in that realm to any service in that realm. This vulnerability can only be closed by disabling cross-realm authentication in Kerberos IV (CAN-2003-0138). Vulnerabilities have been found in the RPC library used by the kadmin service in Kerberos 5. A faulty length check in the RPC library exposes kadmind to an integer overflow which can be used to crash kadmind (CAN-2003-0028). The Key Distribution Center (KDC) allows remote, authenticatedattackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes the KDC to corrupt its heap (CAN-2003-0082). All users of Kerberos are advised to upgrade to these errata packages, which disable cross-realm authentication by default for Kerberos IV and which contain patches that correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. RPMs required: Red Hat Linux 9: SRPMS: i386: 6. Verification: MD5 sum Package Name --------------------------------------------------------------------------a8520da58b790a356d0a94ae75f7957b 9/en/os/SRPMS/krb5-1.2.7-14.src.rpm 49e7783cb50c3694411b7856d098eff5 9/en/os/i386/krb5-devel-1.2.7-14.i386.rpm 6cb5040d3a4bd21a801e8c1e5da6388d 9/en/os/i386/krb5-libs-1.2.7-14.i386.rpm 8eb2a755c2fdf52b779960ec66cc6783 9/en/os/i386/krb5-server-1.2.7-14.i386.rpm bbcde88fa4f273c7c45a927dc5b40d58 9/en/os/i386/krb5-workstation-1.2.7-14.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available at All Red Hat products You can verify each package with the following command: rpm --checksig-v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: mit mit mit -CAN-2003-0028 CAN-2003-0082 CAN-2003-0138 CAN-2003-0139 8. Contact: The Red Hat security contact is . More contact details at All Red Hat products Copyright 2003 Red Hat, Inc. _______________________________________________ Red Hat-watch-list mailing list To unsubscribe, visit: `. Updated Kerberos packages for Red Hat Linux 9 fix critical vulnerabilities affecting authentication functionality.. Red Hat Linux, Kerberos Security Patches, Authentication Problems. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 15, 2023 Critical Red Hat
87

Debian Bullseye: DSA-5200-1 Moderate: LibTIRPC Denial Of Service Risk

It was discovered that libtirpc, a transport-independent RPC library, does not properly handle idle TCP connections. A remote attacker can take advantage of this flaw to cause a denial of service. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5200-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso August 07, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libtirpc CVE ID : CVE-2021-46828 Debian Bug : 1015873 It was discovered that libtirpc, a transport-independent RPC library, does not properly handle idle TCP connections. A remote attacker can take advantage of this flaw to cause a denial of service. For the stable distribution (bullseye), this problem has been fixed in version 1.3.1-1+deb11u1. We recommend that you upgrade your libtirpc packages. For the detailed security status of libtirpc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libtirpc Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . To fix the idle TCP connection vulnerability in Debian, upgrade libtirpc to the latest version. Follow the outlined steps to ensure security. libtirpc Update, Debian Security Threat, RPC Library Risk. . LinuxSecurity.com Team

Calendar 2 Aug 07, 2022 Debian
200

Scientific Linux SL5.x: 2007-09-04 Critical: krb5 Buffer Overflow

Important: krb5 security update. Date: Wed, 5 Sep 2007 08:57:59 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for krb5 on SL5.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Important: krb5 security update Issue date: 2007-09-04 CVE Names: CVE-2007-3999 CVE-2007-4000 Tenable Network Security discovered a stack buffer overflow flaw in the RPC library used by kadmind. A remote unauthenticated attacker who can access kadmind could trigger this flaw and cause kadmind to crash. On Red Hat Enterprise Linux 5 it is not possible to exploit this flaw to run arbitrary code as the overflow is blocked by FORTIFY_SOURCE. (CVE-2007-3999) Garrett Wollman discovered an uninitialized pointer flaw in kadmind. A remote unauthenticated attacker who can access kadmind could trigger this flaw and cause kadmind to crash. (CVE-2007-4000) SL 5.x SRPMS: krb5-1.5-28.src.rpm i386: krb5-devel-1.5-28.i386.rpm krb5-libs-1.5-28.i386.rpm krb5-server-1.5-28.i386.rpm krb5-workstation-1.5-28.i386.rpm x86_64: krb5-devel-1.5-28.i386.rpm krb5-devel-1.5-28.x86_64.rpm krb5-libs-1.5-28.i386.rpm krb5-libs-1.5-28.x86_64.rpm krb5-server-1.5-28.x86_64.rpm krb5-workstation-1.5-28.x86_64.rpm -Connie Sieh -Troy Dawson . Critical patch released for OpenSSL mitigates potential DDoS attacks in Ubuntu Server 18.04.. krb5 Security Update, Scientific Linux Advisory, Buffer Overflow Fix, Remote Access Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 05, 2007 Critical Scientific Linux
98

Red Hat Enterprise Linux 2.1 Moderate: Critical KRB5 Buffer Overflow Alert

Updated krb5 packages that fix several security flaws are now available for Red Hat Enterprise Linux 2.1 and 3. David Coffey discovered an uninitialized pointer free flaw in the RPC library used by kadmind. A remote unauthenticated attacker who can access kadmind could trigger this flaw and cause kadmind to crash or potentially execute arbitrary code as root. This update has been rated as having critical security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Critical: krb5 security update Advisory ID: RHSA-2007:0384-01 Advisory URL: https://access.redhat.com/errata/RHSA-2007:0384.html Issue date: 2007-06-26 Updated on: 2007-06-26 Product: Red Hat Enterprise Linux CVE Names: CVE-2007-2442 CVE-2007-2443 CVE-2007-2798 - ---------------------------------------------------------------------1. Summary: Updated krb5 packages that fix several security flaws are now available for Red Hat Enterprise Linux 2.1 and 3. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: Kerberos is a network authentication system which allows clients and servers to authenticate to each other through use of symmetric encryption and a trusted third party, the KDC. kadmind is the KADM5 administration server. David Coffey discovered an uninitialized pointer free flaw in theRPC library used by kadmind. A remote unauthenticated attacker who can access kadmind could trigger this flaw and cause kadmind to crash or potentially execute arbitrary code as root. (CVE-2007-2442) David Coffey also discovered an overflow flaw in the RPC library used by kadmind. On Red Hat Enterprise Linux, exploitation of this flaw is limited to a denial of service. A remote unauthenticated attacker who can access kadmind could trigger this flaw and cause kadmind to crash. (CVE-2007-2443) A stack buffer overflow flaw was found in kadmind. An authenticated attacker who can access kadmind could trigger this flaw and potentially execute arbitrary code on the Kerberos server. (CVE-2007-2798) For Red Hat Enterprise Linux 2.1, several portability bugs which would lead to unexpected crashes on the ia64 platform have also been fixed. Users of krb5-server are advised to update to these erratum packages which contain backported fixes to correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bug IDs fixed (http://bugzilla.redhat.com/): 241590 - kadmin core dumps on ia64 245547 - CVE-2007-2442 krb5 RPC library unitialized pointer free 245548 - CVE-2007-2443 krb5 RPC library stack overflow 245549 - CVE-2007-2798 krb5 kadmind buffer overflow 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: c0a472af62885afe44869b685187b346 krb5-1.2.2-47.src.rpm i386: 125ca9d18f3020e3f4f9fbb2f9f826bb krb5-devel-1.2.2-47.i386.rpm d579acc559fc428f2ae971acb848ef7d krb5-libs-1.2.2-47.i386.rpm 76d8f32be9bf0686034940f56c5be90d krb5-server-1.2.2-47.i386.rpm 44dbf354346c59c318097f867aea368a krb5-workstation-1.2.2-47.i386.rpm ia64: 2a4c48bdf2cb8dac81f671dfde23e755 krb5-devel-1.2.2-47.ia64.rpm 0ab61f4ec73d0d61b074a1d7cae707d5 krb5-libs-1.2.2-47.ia64.rpm 08c6d5c92fd584d3560b748254804eb5 krb5-server-1.2.2-47.ia64.rpm 3849e726f6124a0b7f80945456ddcca5 krb5-workstation-1.2.2-47.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: c0a472af62885afe44869b685187b346 krb5-1.2.2-47.src.rpm ia64: 2a4c48bdf2cb8dac81f671dfde23e755 krb5-devel-1.2.2-47.ia64.rpm 0ab61f4ec73d0d61b074a1d7cae707d5 krb5-libs-1.2.2-47.ia64.rpm 08c6d5c92fd584d3560b748254804eb5 krb5-server-1.2.2-47.ia64.rpm 3849e726f6124a0b7f80945456ddcca5 krb5-workstation-1.2.2-47.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: c0a472af62885afe44869b685187b346 krb5-1.2.2-47.src.rpm i386: 125ca9d18f3020e3f4f9fbb2f9f826bb krb5-devel-1.2.2-47.i386.rpm d579acc559fc428f2ae971acb848ef7d krb5-libs-1.2.2-47.i386.rpm 76d8f32be9bf0686034940f56c5be90d krb5-server-1.2.2-47.i386.rpm 44dbf354346c59c318097f867aea368a krb5-workstation-1.2.2-47.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: c0a472af62885afe44869b685187b346 krb5-1.2.2-47.src.rpm i386: 125ca9d18f3020e3f4f9fbb2f9f826bb krb5-devel-1.2.2-47.i386.rpm d579acc559fc428f2ae971acb848ef7d krb5-libs-1.2.2-47.i386.rpm 76d8f32be9bf0686034940f56c5be90d krb5-server-1.2.2-47.i386.rpm 44dbf354346c59c318097f867aea368a krb5-workstation-1.2.2-47.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: 3c8baf93bf7295fa4d54ddfe70a1d64c krb5-1.2.7-66.src.rpm i386: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm 4539662077e2665841719421577fabf0 krb5-devel-1.2.7-66.i386.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm 0e3c37a98128874c57ba3abbadc38b84 krb5-server-1.2.7-66.i386.rpm 4ebc7d0ce73b684e41e77faf24eaba01 krb5-workstation-1.2.7-66.i386.rpm ia64: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm b8cd4e290bf54897fb9c11deeaf1212c krb5-debuginfo-1.2.7-66.ia64.rpm 529e3dfe9091f87d2650a6344c53166b krb5-devel-1.2.7-66.ia64.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm b62a442ee20acbabaab8ead16fdedd3b krb5-libs-1.2.7-66.ia64.rpm 788c56657cb17d70ba6bc8234fc7fec9 krb5-server-1.2.7-66.ia64.rpm e19f3d0be15fc78f7bad73fff5d85bb6 krb5-workstation-1.2.7-66.ia64.rpm ppc: 05b40a6263d6749601e1e8f865b60b80 krb5-debuginfo-1.2.7-66.ppc.rpm 3fdb2910f4ac90a6e6092ff0c330d415 krb5-debuginfo-1.2.7-66.ppc64.rpm e2101aaee531d1172bbd8b711fa991f3 krb5-devel-1.2.7-66.ppc.rpm 5377f429ed05bffd2b33e7ad194d608b krb5-libs-1.2.7-66.ppc.rpm 36af2aba242b084e1e97c9d922fb07e8 krb5-libs-1.2.7-66.ppc64.rpm fdd47ad4d343841edc410ff09c956891 krb5-server-1.2.7-66.ppc.rpm 4ef7b91f106e902fcccf185a5ecb18f7 krb5-workstation-1.2.7-66.ppc.rpm s390: 30005e9116e97a5ce1f1bfbbdf52225c krb5-debuginfo-1.2.7-66.s390.rpm dbeb7841edded59a0585ae3caf807495 krb5-devel-1.2.7-66.s390.rpm 9a0bb39351602a096dffc95007de2359 krb5-libs-1.2.7-66.s390.rpm 7440dda54fa3a23702ae78725f864aa3 krb5-server-1.2.7-66.s390.rpm d1c7fd28d6bbb4dbbe259f0239997f46 krb5-workstation-1.2.7-66.s390.rpm s390x: 30005e9116e97a5ce1f1bfbbdf52225c krb5-debuginfo-1.2.7-66.s390.rpm b536151f4b3aff84e985008e8b6e84bf krb5-debuginfo-1.2.7-66.s390x.rpm a16888885ce6231b6e83e86e43882aa0 krb5-devel-1.2.7-66.s390x.rpm 9a0bb39351602a096dffc95007de2359 krb5-libs-1.2.7-66.s390.rpm 8cddf8d55a7475eb60e21d8966010ea4 krb5-libs-1.2.7-66.s390x.rpm 09ef57a4b90409b7f2930afed65a57d9 krb5-server-1.2.7-66.s390x.rpm 031df9b0b3514aaffeba15844098323e krb5-workstation-1.2.7-66.s390x.rpm x86_64: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm 02d01b6ca0f41bd5fed897c46d6510e3 krb5-debuginfo-1.2.7-66.x86_64.rpm 1c70754189ca4fbd1a37c60d6b8a5ac4 krb5-devel-1.2.7-66.x86_64.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm a9f69c0d1c72d7292d0aa99275120b65 krb5-libs-1.2.7-66.x86_64.rpm 3808cda78fdeae3cb6315dbdad962703 krb5-server-1.2.7-66.x86_64.rpm 0fc7048dbb02e0d49d8a3b46fcb7c9a6 krb5-workstation-1.2.7-66.x86_64.rpm Red Hat Desktop version 3: SRPMS: 3c8baf93bf7295fa4d54ddfe70a1d64c krb5-1.2.7-66.src.rpm i386: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm 4539662077e2665841719421577fabf0 krb5-devel-1.2.7-66.i386.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm 0e3c37a98128874c57ba3abbadc38b84 krb5-server-1.2.7-66.i386.rpm 4ebc7d0ce73b684e41e77faf24eaba01 krb5-workstation-1.2.7-66.i386.rpm x86_64: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm 02d01b6ca0f41bd5fed897c46d6510e3 krb5-debuginfo-1.2.7-66.x86_64.rpm 1c70754189ca4fbd1a37c60d6b8a5ac4 krb5-devel-1.2.7-66.x86_64.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm a9f69c0d1c72d7292d0aa99275120b65 krb5-libs-1.2.7-66.x86_64.rpm 3808cda78fdeae3cb6315dbdad962703 krb5-server-1.2.7-66.x86_64.rpm 0fc7048dbb02e0d49d8a3b46fcb7c9a6 krb5-workstation-1.2.7-66.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 3c8baf93bf7295fa4d54ddfe70a1d64c krb5-1.2.7-66.src.rpm i386: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm 4539662077e2665841719421577fabf0 krb5-devel-1.2.7-66.i386.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm 0e3c37a98128874c57ba3abbadc38b84 krb5-server-1.2.7-66.i386.rpm 4ebc7d0ce73b684e41e77faf24eaba01 krb5-workstation-1.2.7-66.i386.rpm ia64: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm b8cd4e290bf54897fb9c11deeaf1212c krb5-debuginfo-1.2.7-66.ia64.rpm 529e3dfe9091f87d2650a6344c53166b krb5-devel-1.2.7-66.ia64.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm b62a442ee20acbabaab8ead16fdedd3b krb5-libs-1.2.7-66.ia64.rpm 788c56657cb17d70ba6bc8234fc7fec9 krb5-server-1.2.7-66.ia64.rpm e19f3d0be15fc78f7bad73fff5d85bb6 krb5-workstation-1.2.7-66.ia64.rpm x86_64: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm 02d01b6ca0f41bd5fed897c46d6510e3 krb5-debuginfo-1.2.7-66.x86_64.rpm 1c70754189ca4fbd1a37c60d6b8a5ac4 krb5-devel-1.2.7-66.x86_64.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm a9f69c0d1c72d7292d0aa99275120b65 krb5-libs-1.2.7-66.x86_64.rpm 3808cda78fdeae3cb6315dbdad962703 krb5-server-1.2.7-66.x86_64.rpm 0fc7048dbb02e0d49d8a3b46fcb7c9a6 krb5-workstation-1.2.7-66.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 3c8baf93bf7295fa4d54ddfe70a1d64c krb5-1.2.7-66.src.rpm i386: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm 4539662077e2665841719421577fabf0 krb5-devel-1.2.7-66.i386.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm 0e3c37a98128874c57ba3abbadc38b84 krb5-server-1.2.7-66.i386.rpm 4ebc7d0ce73b684e41e77faf24eaba01 krb5-workstation-1.2.7-66.i386.rpm ia64: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm b8cd4e290bf54897fb9c11deeaf1212c krb5-debuginfo-1.2.7-66.ia64.rpm 529e3dfe9091f87d2650a6344c53166b krb5-devel-1.2.7-66.ia64.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm b62a442ee20acbabaab8ead16fdedd3b krb5-libs-1.2.7-66.ia64.rpm 788c56657cb17d70ba6bc8234fc7fec9 krb5-server-1.2.7-66.ia64.rpm e19f3d0be15fc78f7bad73fff5d85bb6 krb5-workstation-1.2.7-66.ia64.rpm x86_64: ac401d5a3e5a7d29e807c230f4c10c32 krb5-debuginfo-1.2.7-66.i386.rpm 02d01b6ca0f41bd5fed897c46d6510e3 krb5-debuginfo-1.2.7-66.x86_64.rpm 1c70754189ca4fbd1a37c60d6b8a5ac4 krb5-devel-1.2.7-66.x86_64.rpm 254ab5c46c2ba7f24f43b34ed9e7d198 krb5-libs-1.2.7-66.i386.rpm a9f69c0d1c72d7292d0aa99275120b65 krb5-libs-1.2.7-66.x86_64.rpm 3808cda78fdeae3cb6315dbdad962703 krb5-server-1.2.7-66.x86_64.rpm 0fc7048dbb02e0d49d8a3b46fcb7c9a6 krb5-workstation-1.2.7-66.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7.References: https://www.cve.org/CVERecord?id=CVE-2007-2442 https://www.cve.org/CVERecord?id=CVE-2007-2443 https://www.cve.org/CVERecord?id=CVE-2007-2798 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2007 Red Hat, Inc. . Essential krb5 patch released by Red Hat targets various security flaws impacting commercial Linux environments.. Red Hat Enterprise Linux, krb5 security, buffer overflow, critical update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 29, 2007 Critical Red Hat
89

Fedora: FEDORA-2007-620 Critical Update for krb5 Buffer Overflow Issue

This update incorporates fixes for a stack buffer overflow and heap corruption in the RPC library, and a fix for a potential stack buffer overflow in kadmind.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2007-620 2007-06-28 ---------------------------------------------------------------------Product : Fedora Core 5 Name : krb5 Version : 1.4.3 Release : 5.5 Summary : The Kerberos network authentication system. Description : Kerberos V5 is a trusted-third-party network authentication system, which can improve your network's security by eliminating the insecure practice of cleartext passwords. ---------------------------------------------------------------------Update Information: This update incorporates fixes for a stack buffer overflow and heap corruption in the RPC library, and a fix for a potential stack buffer overflow in kadmind. ---------------------------------------------------------------------* Wed Jun 27 2007 Nalin Dahyabhai 1.4.3-5.5 - incorporate fixes for MITKRB5-SA-2007-004 (CVE-2007-2442,CVE-2007-2443) and MITKRB5-SA-2007-005 (CVE-2007-2798) * Tue Apr 3 2007 Nalin Dahyabhai 1.4.3-5.4 - add patch to correct unauthorized access via krb5-aware telnet daemon (#229782, CVE-2007-0956) - add patch to fix buffer overflow in krb5kdc and kadmind (#231528, CVE-2007-0957) - add patch to fix double-free in kadmind (#231537, CVE-2007-1216) * Tue Jan 9 2007 Nalin Dahyabhai 1.4.3-5.3 - apply patch from Tom Yu to fix MITKRB-SA-2006-002 (CVE-2006-6143) * Fri Aug 18 2006 Nalin Dahyabhai 1.4.3-5.2 - switch to the updated patch for MITKRB-SA-2006-001 * Tue Aug 8 2006 Nalin Dahyabhai 1.4.3-5.1 - apply patch to address MITKRB-SA-2006-001 (CVE-2006-3084) * Fri Apr 14 2006 Stepan Kasal - 1.4.3-5 - Fix formatting typo in kinit.1 (krb5-kinit-man-typo.patch) ---------------------------------------------------------------------This update can be downloaded from: 428f5a1a16f261507e780a7468adcf054534228a SRPMS/krb5-1.4.3-5.5.src.rpm 428f5a1a16f261507e780a7468adcf054534228a noarch/krb5-1.4.3-5.5.src.rpm ae9338cee91736eab3a108b8713d4dce56e1e41e ppc/debug/krb5-debuginfo-1.4.3-5.5.ppc.rpm 7a6a044dbe79c2b1e52bb37493a125c81ec3d61a ppc/krb5-server-1.4.3-5.5.ppc.rpm 28f4db0ea0ee174c3d027b387e2dc1de3743920a ppc/krb5-libs-1.4.3-5.5.ppc.rpm b2b2e49c40a4f2f9896e1968533df905c9bf5a17 ppc/krb5-workstation-1.4.3-5.5.ppc.rpm d5138a1387d0c53555f30b62453c4acc48c3f850 ppc/krb5-devel-1.4.3-5.5.ppc.rpm fb2b5ee96faeb4a32e5ebef492e3951f884be0b7 x86_64/debug/krb5-debuginfo-1.4.3-5.5.x86_64.rpm c38ff027c2fc12e2f5574978d447d3312f46c083 x86_64/krb5-server-1.4.3-5.5.x86_64.rpm ae8e4ccde571e411765b76813df63179cccb14b0 x86_64/krb5-libs-1.4.3-5.5.x86_64.rpm a429a9a7e6bc3716bc3762aed47949aafce2fe93 x86_64/krb5-devel-1.4.3-5.5.x86_64.rpm 4097c5826880d51c689cc2ac9598865d2d963d2e x86_64/krb5-workstation-1.4.3-5.5.x86_64.rpm dbfb9c6daf7737dba40ef46ee83311179664eddd i386/krb5-devel-1.4.3-5.5.i386.rpm b1d93b42f28f0722f758493897ee8036cce1d8ab i386/krb5-server-1.4.3-5.5.i386.rpm 0d7d3f5d147c26f023e16c5c21f45716bfc04ab2 i386/krb5-libs-1.4.3-5.5.i386.rpm 08bb2e80ac94de576b5bc6129c329fed91e215c1 i386/krb5-workstation-1.4.3-5.5.i386.rpm 270cb51345181477d454f97015af76c5b303a25e i386/debug/krb5-debuginfo-1.4.3-5.5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Mitigations for buffer overflow vulnerabilities and heap corruption in Fedora Core 5's krb5 are vital for enhancing network security and preventing exploits. Fedora Core, NetworkAuthentication, Stack Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 29, 2007 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here