漏洞信息详情
MIT Kerberos 5 Principal Name缓冲区溢出漏洞
- CNNVD编号:CNNVD-200304-016
- 危害等级: 中危
- CVE编号:
CVE-2003-0082
- 漏洞类型:
边界条件错误
- 发布时间:
2003-04-02
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
mit - 漏洞来源:
Discovery is credi… -
漏洞简介
Kerberos 5 (krb5) 1.2.7及其之前版本的Key Distribution Center (KDC)存在漏洞。远程认证攻击者使用导致KDC堆损坏(又称为 \”buffer underrun\”)的一个特定协议请求导致具有相同域的KDCs服务拒绝(崩溃)。
漏洞公告
Debian has released a security advisory [DSA 266-1] containing fixes for
this issue.
Conectiva has released a security advisory (CLA-2003:639) containing fixes which address this issue. Users are advised to upgrade as soon as possible.
Sun has released alert 54042 to address this issue.
The following fixes are available:
Sun Solaris 9
-
Sun 112908-10Solaris 9 Sparc
http://sunsolve.sun.com -
Sun 112921-02Solaris 9 Sparc
http://sunsolve.sun.com -
Sun 112923-03Solaris 9 Sparc
http://sunsolve.sun.com -
Sun 112925-03Solaris 9 Sparc
http://sunsolve.sun.com
Sun Solaris 9_x86
-
Sun 113990-04Solaris 9 Intel
http://sunsolve.sun.com -
Sun 115168-02Solaris 9 Intel
http://sunsolve.sun.com -
Sun 116044-01Solaris 9 Intel
http://sunsolve.sun.com -
Sun 116045-01Solaris 9 Intel
http://sunsolve.sun.com -
Sun 116046-03Solaris 9 Intel
http://sunsolve.sun.com
Sun Solaris 8_x86
-
Sun 116044-01Solaris 9 Intel
http://sunsolve.sun.com -
Sun 112238-08Solaris 8 Intel
http://sunsolve.sun.com -
Sun 112240-07Solaris 8 Intel
http://sunsolve.sun.com
Sun Solaris 8
-
Sun 112237-09Solaris 8 Sparc
http://sunsolve.sun.com -
Sun 112390-08Solaris 8 Sparc
http://sunsolve.sun.com
MIT Kerberos 5 1.0
-
MIT MITKRB5-SA-2003-005-patch.txt
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-patch.t
xt
Sun SEAM 1.0
-
Sun 110057-07Solaris 2.6 Sparc
http://sunsolve.sun.com -
Sun 110058-07Solaris 7 Intel
http://sunsolve.sun.com -
Sun 110057-07Solaris 7 Sparc
http://sunsolve.sun.com -
Sun 110058-07 Solaris 2.6 Intel
http://sunsolve.sun.com -
Sun 112534-03Solaris 2.6 Sparc
http://sunsolve.sun.com -
Sun 112535-03Solaris 2.6 Intel
http://sunsolve.sun.com -
Sun 112536-04Solaris 7 Sparc
http://sunsolve.sun.com -
Sun 112537-04Solaris 7 Intel
http://sunsolve.sun.com
Sun SEAM 1.0.1
-
Sun 110060-14Solaris 8 Sparc
http://sunsolve.sun.com -
Sun 110061-14Solaris 8 Intel
http://sunsolve.sun.com
Sun SEAM 1.0.2
-
Sun 116462-01Solaris 9 Sparc
http://sunsolve.sun.com
MIT Kerberos 5 1.0.6
-
MIT MITKRB5-SA-2003-005-patch.txt
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-patch.t
xt
MIT Kerberos 5 1.1
-
MIT MITKRB5-SA-2003-005-patch.txt
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-patch.t
xt
MIT Kerberos 5 1.1.1
-
MIT MITKRB5-SA-2003-005-patch.txt
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-patch.t
xt -
Red Hat krb5-configs-1.1.1-40.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/krb5-configs-1.1.1-40.i386.rpm
-
Red Hat krb5-devel-1.1.1-40.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/krb5-devel-1.1.1-40.i386.rpm -
Red Hat krb5-libs-1.1.1-40.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/krb5-libs-1.1.1-40.i386.rpm -
Red Hat krb5-server-1.1.1-40.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/krb5-server-1.1.1-40.i386.rpm -
Red Hat krb5-workstation-1.1.1-40.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/krb5-workstation-1.1.1-40.i386
.rpm
MIT Kerberos 5 1.2
-
MIT MITKRB5-SA-2003-005-patch.txt
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-patch.t
xt
MIT Kerberos 5 1.2.1
-
MIT MITKRB5-SA-2003-005-patch.txt
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-patch.t
xt
MIT Kerberos 5 1.2.2
-
MandrakeSoft ftp-client-krb5-1.2.2-17.5mdk.i586.rpmMandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft ftp-client-krb5-1.2.2-17.5mdk.ppc.rpmMandrake Linux 8.2/PPC
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft ftp-server-krb5-1.2.2-17.5mdk.i586.rpmMandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft ftp-server-krb5-1.2.2-17.5mdk.ppc.rpmMandrake Linux 8.2/PPC
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-devel-1.2.2-17.5mdk.i586.rpmMandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-devel-1.2.2-17.5mdk.ppc.rpmMandrake Linux 8.2/PPC
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft krb5-libs-1.2.2-17.5mdk.i586.rpmMandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php - M
参考网址
来源: DEBIAN
名称: DSA-266
链接:http://www.debian.org/security/2003/dsa-266
来源: web.mit.edu
链接:http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt
来源: REDHAT
名称: RHSA-2003:091
链接:http://www.redhat.com/support/errata/RHSA-2003-091.html
来源: REDHAT
名称: RHSA-2003:052
链接:http://www.redhat.com/support/errata/RHSA-2003-052.html
来源: REDHAT
名称: RHSA-2003:051
链接:http://www.redhat.com/support/errata/RHSA-2003-051.html
来源: BID
名称: 7185
链接:http://www.securityfocus.com/bid/7185
来源: BUGTRAQ
名称: 20030331 GLSA: krb5 & mit-krb5 (200303-28)
链接:http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded
来源: SUNALERT
名称: 54042
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1
来源: US Government Resource: oval:org.mitre.oval:def:4430
名称: oval:org.mitre.oval:def:4430
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4430
来源: US Government Resource: oval:org.mitre.oval:def:2536
名称: oval:org.mitre.oval:def:2536
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2536
来源: US Government Resource: oval:org.mitre.oval:def:244
名称: oval:org.mitre.oval:def:244
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:244