Heimdal Kerberos转发守护程序零终止字符串绕过缓冲区溢出漏洞

漏洞信息详情

Heimdal Kerberos转发守护程序零终止字符串绕过缓冲区溢出漏洞

漏洞简介

带有未知影响的Heimdal 0.5之前版本可能在(1)kadmind以及(2)kdc服务器中存在未知漏洞。远程或本地攻击者可能获得根或其他使用权,但是不借助缓冲区溢出(CVE-2002-1225)。

漏洞公告

NetBSD has released an advisory addressing this issue. All versions of NetBSD, including NetBSD-current source prior to September 10, 2002, contain the vulnerable binary, though the service is not enabled by default. NetBSD has fixed this version vulnerability in the 1.5 version of the source, and the 1.6 branch fix is pending. NetBSD Security has advised users of 1.6 to manually remove the vulnerable binaries after completing a “make build”.
Users of Gentoo Linux are advised to upgrade using the following commands:
emerge rsync
emerge heimdal
emerge clean
Updated versions available:
KTH Heimdal 0.3 e

KTH Heimdal 0.4 d

KTH Heimdal 0.4 b

KTH Heimdal 0.4 c

KTH Heimdal 0.4 e

参考网址

来源: DEBIAN
名称: DSA-178
链接:http://www.debian.org/security/2002/dsa-178

来源: SUSE
名称: SuSE-SA:2002:034
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=103341355708817&w=2

来源: BUGTRAQ
名称: 20021014 GLSA: heimdal
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=103462479621246&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享