Login
Newsletter
Werbung

Sicherheit: Denial of Service in Kerberos
Aktuelle Meldungen Distributionen
Name: Denial of Service in Kerberos
ID: USN-1290-1
Distribution: Ubuntu
Plattformen: Ubuntu 11.10
Datum: Do, 8. Dezember 2011, 09:26
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1530
Applikationen: Kerberos

Originalnachricht


--===============3079797864100324618==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="Clx92ZfkiYIKRjnr"
Content-Disposition: inline


--Clx92ZfkiYIKRjnr
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-1290-1
December 08, 2011

krb5 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10

Summary:

The Kerberos Key Distribution Center (KDC) could be made to crash.

Software Description:
- krb5: MIT Kerberos Network Authentication Protocol

Details:

Simo Sorce discovered that a NULL pointer dereference existed in
the Kerberos Key Distribution Center (KDC). An authenticated remote
attacker could use this to cause a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
krb5-kdc 1.9.1+dfsg-1ubuntu2.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1290-1
CVE-2011-1530

Package Information:
https://launchpad.net/ubuntu/+source/krb5/1.9.1+dfsg-1ubuntu2.2


--Clx92ZfkiYIKRjnr
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCgAGBQJO4AjFAAoJEC8Jno0AXoH04QIP/1CSKtiC3lhuIVjiIAOkCggj
OU0ohK3gLBb65mOewXiD2bczpFkgOjcDVViW6zEonu7N6u1PKODDyuTri6SemmM1
qAWTUZLJbcB+g0IHA/zfowAGwYeQbfSlmbRkSz5WCVxk/4FaG/oWqFjmqkHOuww+
OZhl+/rGzB2/e8IMzKLkiZqgfrsE04Pu5B0UB46mmeBIpuKk+SO9UUosw9roo3Oz
kbgWhegKeFTmgM6m7yUhC5sePQjf92dbJjgS5BWBpQ5b6Wtx9eQ/W73wVjyREkSf
yeD2szh6fHl0Uuii1V4je52MANnNiOTFf0ak2b2j8Rg/nWywu5H7K4RlQU8gmuAO
BIc+1+2b0QtJH0qIl0Ch6R/jq3AjY1ERebHORU/lveCArDNzwu/EZ9wE7KrL2si1
95VI2NqChQIWNgqA+A7dUpkIX9bKVl3jCu/w/SmYlcuyb4MnYybQQH5gME/qrXMg
E3ODksz1wtiGrRzF5tZoVAjzxdsos18E2EOI0aku2f8qZosIPiR9qkflntfCCCgG
PwnUzHuQuAQ3LKKFNlhVlmT5PZPszlUEy7h9dmPGiXCvo3MJURZx0C1qbWiaApbq
Y8NVx4NkULv50Dn/NXQvpQsiWEPwkBMgZ5CU5qE9aMMHJ5bLJf05h55z6ZpsCyAz
PVpsFZJdvexbvN0Z+8OG
=xLX2
-----END PGP SIGNATURE-----

--Clx92ZfkiYIKRjnr--


--===============3079797864100324618==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============3079797864100324618==--
Pro-Linux
Traut euch!
Neue Nachrichten
Werbung