View Full Version : USN-511-1: Kerberos vulnerability

September 5th, 2007, 03:20 AM
Referenced CVEs:

================================================== ========= Ubuntu Security Notice USN-511-1 September 04, 2007 krb5, librpcsecgss vulnerability CVE-2007-3999 ================================================== ========= A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libkadm55 1.4.3-5ubuntu0.5 librpcsecgss1 0.7-0ubuntu1.1 Ubuntu 6.10: libkadm55 1.4.3-9ubuntu1.4 librpcsecgss2 0.13-2ubuntu0.1 Ubuntu 7.04: libkadm55 1.4.4-5ubuntu3.2 librpcsecgss3 0.14-2ubuntu1.1 In general, a standard system upgrade is sufficient to affect the necessary changes. Details follow: It was discovered that the libraries handling RPCSEC_GSS did not correctly validate the size of certain packet structures. An unauthenticated remote user could send a specially crafted request and execute arbitrary code with root privileges.

More... (http://www.ubuntu.com/usn/usn-511-1)