View Full Version : USN-511-2: Kerberos vulnerability

September 7th, 2007, 10:40 PM
Referenced CVEs:

================================================== ========= Ubuntu Security Notice USN-511-2 September 07, 2007 krb5, librpcsecgss vulnerability CVE-2007-4743 ================================================== ========= A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libkadm55 1.4.3-5ubuntu0.6 librpcsecgss1 0.7-0ubuntu1.2 Ubuntu 6.10: libkadm55 1.4.3-9ubuntu1.5 librpcsecgss2 0.13-2ubuntu0.2 Ubuntu 7.04: libkadm55 1.4.4-5ubuntu3.3 librpcsecgss3 0.14-2ubuntu1.2 In general, a standard system upgrade is sufficient to affect the necessary changes. Details follow: USN-511-1 fixed vulnerabilities in krb5 and librpcsecgss. The fixes were incomplete, and only reduced the scope of the vulnerability, without fully solving it. This update fixes the problem. Original advisory details: It was discovered that the libraries handling RPCSEC_GSS did not correctly validate the size of certain packet structures. An unauthenticated remote user could send a specially crafted request and execute arbitrary code with root privileges.

More... (http://www.ubuntu.com/usn/usn-511-2)