Summary: | <app-crypt/mit-krb5-1.7.1 DOS (CVE-2009-4212,CVE-2010-0283) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Stefan Behte (RETIRED) <craig> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | kerberos |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=545015 | ||
Whiteboard: | B3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Stefan Behte (RETIRED)
2010-03-06 14:49:14 UTC
http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-004.txt Patches: http://web.mit.edu/kerberos/advisories/2009-004-patch_1.7.txt http://web.mit.edu/kerberos/advisories/2009-004-patch_1.6.3.txt Please provide an updated ebuild. CVE-2010-0283 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0283): The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request. The oldest version in the tree is now 1.8.3. A B3-rated vulnerability gets a GLSA vote. GLSA Vote: yes. Yes, added to glsa for #323525. This issue was resolved and addressed in GLSA 201201-13 at http://security.gentoo.org/glsa/glsa-201201-13.xml by GLSA coordinator Sean Amoss (ackle). |