MIT Kerberos 5 Principal Name缓冲区溢出漏洞

漏洞信息详情

MIT Kerberos 5 Principal Name缓冲区溢出漏洞

漏洞简介

Kerberos 5 (krb5) 1.2.7及其之前版本的Key Distribution Center (KDC)存在漏洞。远程认证攻击者使用导致KDC堆损坏(又称为 \”buffer underrun\”)的一个特定协议请求导致具有相同域的KDCs服务拒绝(崩溃)。

漏洞公告

Debian has released a security advisory [DSA 266-1] containing fixes for
this issue.
Conectiva has released a security advisory (CLA-2003:639) containing fixes which address this issue. Users are advised to upgrade as soon as possible.
Sun has released alert 54042 to address this issue.
The following fixes are available:
Sun Solaris 9

Sun Solaris 9_x86

Sun Solaris 8_x86

Sun Solaris 8

MIT Kerberos 5 1.0

Sun SEAM 1.0

Sun SEAM 1.0.1

Sun SEAM 1.0.2

MIT Kerberos 5 1.0.6

MIT Kerberos 5 1.1

MIT Kerberos 5 1.1.1

MIT Kerberos 5 1.2

MIT Kerberos 5 1.2.1

MIT Kerberos 5 1.2.2

参考网址

来源: DEBIAN
名称: DSA-266
链接:http://www.debian.org/security/2003/dsa-266

来源: web.mit.edu
链接:http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt

来源: REDHAT
名称: RHSA-2003:091
链接:http://www.redhat.com/support/errata/RHSA-2003-091.html

来源: REDHAT
名称: RHSA-2003:052
链接:http://www.redhat.com/support/errata/RHSA-2003-052.html

来源: REDHAT
名称: RHSA-2003:051
链接:http://www.redhat.com/support/errata/RHSA-2003-051.html

来源: BID
名称: 7185
链接:http://www.securityfocus.com/bid/7185

来源: BUGTRAQ
名称: 20030331 GLSA: krb5 & mit-krb5 (200303-28)
链接:http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded

来源: SUNALERT
名称: 54042
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1

来源: US Government Resource: oval:org.mitre.oval:def:4430
名称: oval:org.mitre.oval:def:4430
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4430

来源: US Government Resource: oval:org.mitre.oval:def:2536
名称: oval:org.mitre.oval:def:2536
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2536

来源: US Government Resource: oval:org.mitre.oval:def:244
名称: oval:org.mitre.oval:def:244
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:244

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享