This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Kerberos Multiple Vulns - Update Available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/25800/
Release Date: 2007-06-27
Critical: Highly critical
Impact: DoS. System access
Where: From remote
Solution Status: Vendor Workaround
Software: Kerberos 5.x
…Successful exploitation allows execution of arbitrary code but requires valid user credentials. The vulnerabilities are reported in krb5-1.6.1. Other versions may also be affected.
Solution: Apply patches (see vendor advisories for details).

http://web.mit.edu/kerberos/advisories/2007-004-patch.txt
http://web.mit.edu/kerberos/advisories/200…4-patch.txt.asc

http://web.mit.edu/kerberos/advisories/2007-005-patch.txt
http://web.mit.edu/kerberos/advisories/200…5-patch.txt.asc

Original Advisory: Kerberos:
http://web.mit.edu/kerberos/www/advisories…SA-2007-004.txt
http://web.mit.edu/kerberos/www/advisories…SA-2007-005.txt

> http://www.us-cert.gov/current/#multiple_v…_administration

.
FYI…

- http://secunia.com/advisories/26676/
Release Date: 2007-09-05
Critical: Highly critical
Impact: DoS, System access
Where: From remote
Solution Status: Vendor Workaround
Software: Kerberos 5.x…
Solution: Update to Kerberos 1.5.5 or 1.6.3 as soon as available or apply patches.
http://web.mit.edu/kerberos/advisories/2007-006-patch.txt
Original Advisory:
http://web.mit.edu/kerberos/www/advisories…SA-2007-006.txt …

> http://www.us-cert.gov/current/#multiple_v…administration1

.
FYI…

- http://secunia.com/advisories/29428/
Release Date: 2008-03-19
Critical: Highly critical
Impact: Exposure of sensitive information, DoS, System access
Where: From remote
Solution Status: Vendor Patch
Software: Kerberos 5.x …
Solution: Apply vendor patches.
http://web.mit.edu/kerberos/advisories/2008-001-patch.txt
http://web.mit.edu/kerberos/www/advisories…SA-2008-002.txt …
Original Advisory:
http://web.mit.edu/kerberos/www/advisories…SA-2008-001.txt
http://web.mit.edu/kerberos/www/advisories…SA-2008-002.txt …

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0063

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0062

:ph34r: