First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 141761
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 143240
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 141761 depends on: Show dependency tree
Bug 141761 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-07-26 01:09 0000
The MIT Kerberos Development Team is aware of the following
vulnerabilities in the MIT krb5 software.  Please do not publicly
disseminate this information prior to our public disclosure.

Our current target date for public disclosure is 08 August 2006, not
before 14:00 US/Eastern time.  Vendors should contact tlyu@mit.edu via
PGP-encrypted email for details and patches.  Some vendors already
known to the MIT Kerberos Development Team have been notified
previously.

Please let me know if you have any concerns about the release date.

Advisory MITKRB5-SA-2006-001 concerns the following vulnerabilities:

CVE-2006-3083:

On Linux systems, local privilege escalation vulnerabilities exist in
the krshd and v4rcp programs provided with the MIT implementation of
Kerberos 5 in releases up to and including krb5-1.5.  These
vulnerabilities are due in part to specific properties of Linux.  To
our knowledge, no other operating systems are affected.

CVE-2006-3084:

Local privilege escalation vulnerabilities may exist in the ftpd and
ksu programs provided with the MIT implementation of Kerberos 5 in
releases up to and including krb5-1.5.  To our knowledge, no operating
systems are affected, but there may be operating systems with unknown
specific properties which unmask these vulnerabilities.

------- Comment #1 From Sune Kloppenborg Jeppesen 2006-07-26 02:03:40 0000 -------
Do NEVER open this bug, but open a public when it is time.

------- Comment #2 From Sune Kloppenborg Jeppesen 2006-08-08 12:39:55 0000 -------

*** This bug has been marked as a duplicate of 143240 ***

First Last Prev Next    No search results available      Search page      Enter new bug