First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 52744
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Dan Margolis (RETIRED) <krispykringle@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 52744 depends on: Show dependency tree
Bug 52744 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-06-01 18:59 0000
It seems there's a buffer overflow in MIT's kerberos 5. 

``The krb5_aname_to_localname() library function contains multiple
buffer overflows which could be exploited to gain unauthorized root
access.  Exploitation of these flaws requires an unusual combination
of factors, including successful authentication to a vulnerable
service and a non-default configuration on the target service.  (See
MITIGATING FACTORS below.)  No exploits are known to exist yet.''

It seems that most servers will not be configured in a way that  makes them vulnerable, but if vulnerable, an authenticated user could execute code remotely. See the advisory for more information. 

Reproducible: Always
Steps to Reproduce:
1.
2.
3.

------- Comment #1 From Thierry Carrez (RETIRED) 2004-06-02 02:14:02 0000 -------
Patch for 1.3.3 available at :
http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2004-001-an_to_ln.txt

netmon : please apply patch and bump to 1.3.3-r1

------- Comment #2 From solar 2004-06-02 05:20:40 0000 -------
kerberos vuln.. who would of ever guessed

------- Comment #3 From Thierry Carrez (RETIRED) 2004-06-05 01:37:36 0000 -------
Patch has been recently updated at given URL.

netmon does not have much time for the moment, so security can apply patch with their blessing. If anyone with commit feels like it...

------- Comment #4 From Thierry Carrez (RETIRED) 2004-06-15 12:51:07 0000 -------
netmon herd : if you have more disponibilities now to patch this, as noone in
the security team stepped up yet... We are getting quite late.

------- Comment #5 From Jon Hood (RETIRED) 2004-06-15 14:38:28 0000 -------
Sorry this took so long; I haven't done any security-related bugs before, but
seeing as no one else has worked on this, could everyone please test 1.3.3-r1
which I just put into portage with the suggested patch?

------- Comment #6 From Thierry Carrez (RETIRED) 2004-06-16 01:01:13 0000 -------
Thank you Jon.
Adding all arches for testing : please test and mark app-crypt/mit-krb5-1.3.3-r1 stable.

------- Comment #7 From Bryan Østergaard (RETIRED) 2004-06-17 02:15:19 0000 -------
Stable on alpha.

------- Comment #8 From Jason Wever (RETIRED) 2004-06-17 05:43:40 0000 -------
Stable on sparc.

------- Comment #9 From Guy Martin 2004-06-18 04:55:08 0000 -------
Stable on hppa.

------- Comment #10 From Sune Kloppenborg Jeppesen 2004-06-21 08:23:24 0000 -------
GLSA drafted: security please review.

x86 ppc amd64 please mark stable asap.

------- Comment #11 From SpanKY 2004-06-24 18:00:02 0000 -------
sorry for delay, marked arm stable

btw, wtf is this for:
    CFLAGS=`echo ${CFLAGS} | xargs`
    CXXFLAGS=`echo ${CXXFLAGS} | xargs`
    LDFLAGS=`echo ${LDFLAGS} | xargs`

------- Comment #12 From Thierry Carrez (RETIRED) 2004-06-25 13:54:37 0000 -------
We're getting very late on that one. Other distributions have advisories out
since June 2...

x86, ppc, amd64 : please mark stable so that the GLSA can go out... or report
why you can't mark stable.

------- Comment #13 From Jon Hood (RETIRED) 2004-06-27 20:06:14 0000 -------
I have tested this on stable x86 servers and other systems- it works fine. I
marked it stable on x86 since I got tired of waiting.

------- Comment #14 From Jeremy Huddleston (RETIRED) 2004-06-27 23:26:16 0000 -------
stable on amd64.

------- Comment #15 From Joshua Kinard 2004-06-28 00:13:45 0000 -------
Stable on mips yesterday, removing CC.

------- Comment #16 From Luca Barbato 2004-06-28 13:59:29 0000 -------
Eventually marked ppc, sorry but I was busy

------- Comment #17 From Thierry Carrez (RETIRED) 2004-06-29 00:34:57 0000 -------
This is ready for GLSA publication.
ia64,ppc64,s390 : don't forget to mark stable to benefit from the GLSA.

------- Comment #18 From Kurt Lieber 2004-06-29 09:22:14 0000 -------
glsa 200406-21

------- Comment #19 From Tom Gall 2004-07-13 19:55:58 0000 -------
1.3.1-r1 marked stable on ppc64

First Last Prev Next    No search results available      Search page      Enter new bug