Login
Newsletter
Werbung

Sicherheit: Pufferüberlauf in krb5
Aktuelle Meldungen Distributionen
Name: Pufferüberlauf in krb5
ID: DSA-703-1
Distribution: Debian
Plattformen: Debian woody
Datum: Sa, 2. April 2005, 13:00
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0468
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0469
Applikationen: MIT Kerberos

Originalnachricht

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

--------------------------------------------------------------------------
Debian Security Advisory DSA 703-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
April 1st, 2005 http://www.debian.org/security/faq
--------------------------------------------------------------------------

Package : krb5
Vulnerability : buffer overflows
Problem-Type : remote
Debian-specific: no
CVE IDs : CAN-2005-0468 CAN-2005-0469
CERT advisories: VU#341908 VU#291924

Several problems have been discovered in telnet clients that could be
exploited by malicious daemons the client connects to. The Common
Vulnerabilities and Exposures project identifies the following
problems:

CAN-2005-0468

Gaël Delalleau discovered a buffer overflow in the env_opt_add()
function that allow a remote attacker to execute arbitrary code.

CAN-2005-0469

Gaël Delalleau discovered a buffer overflow in the handling of the
LINEMODE suboptions in telnet clients. This can lead to the
execution of arbitrary code when connected to a malicious server.

For the stable distribution (woody) these problems have been fixed in
version 1.2.4-5woody8.

For the unstable distribution (sid) these problems have been fixed in
version 1.3.6-1.

We recommend that you upgrade your krb5 package.


Upgrade Instructions
--------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
--------------------------------

Source archives:

http://security.debian.org/pool/updates/main/k/krb5/krb5_1.2.4-5woody8.dsc
Size/MD5 checksum: 750 51c3ea6dcf74a9d82bef016509870c3d
krb5_1.2.4-5woody8.diff.gz
Size/MD5 checksum: 83173 97d5ce1eeec763cc67d56b0758891a0f
http://security.debian.org/pool/updates/main/k/krb5/krb5_1.2.4.orig.tar.gz
Size/MD5 checksum: 5443051 663add9b5942be74a86fa860a3fa4167

Architecture independent components:

krb5-doc_1.2.4-5woody8_all.deb
Size/MD5 checksum: 512968 88dea0dcf727a6fe03457485e6c98ea4

Alpha architecture:

krb5-admin-server_1.2.4-5woody8_alpha.deb
Size/MD5 checksum: 253798 4124ad89c3d6698ae5ce09cc0a810e77
krb5-clients_1.2.4-5woody8_alpha.deb
Size/MD5 checksum: 217536 02bdd8e928ce65cfc415de890106cde7
krb5-ftpd_1.2.4-5woody8_alpha.deb
Size/MD5 checksum: 63072 9aa2b092cc3d4729f6d309160b27117c
krb5-kdc_1.2.4-5woody8_alpha.deb
Size/MD5 checksum: 252162 0f2b0638347b34b07ab919c05b7a404a
krb5-rsh-server_1.2.4-5woody8_alpha.deb
Size/MD5 checksum: 76452 4eab68ade26bdd00dc733183f673cf7e
krb5-telnetd_1.2.4-5woody8_alpha.deb
Size/MD5 checksum: 59106 4c00e1ad73ba0be9631ed3b20846cf31
krb5-user_1.2.4-5woody8_alpha.deb
Size/MD5 checksum: 207478 f94b1e493f4a35a9244ab0a71f714f61
libkadm55_1.2.4-5woody8_alpha.deb
Size/MD5 checksum: 83948 b4870cfb49811f9e9bfc182004d6e72a
libkrb5-dev_1.2.4-5woody8_alpha.deb
Size/MD5 checksum: 633440 f794455df495082bd8c40b2f0a6e0f22
libkrb53_1.2.4-5woody8_alpha.deb
Size/MD5 checksum: 367446 248fced4d354d47649deaa0c5d349354

ARM architecture:

krb5-admin-server_1.2.4-5woody8_arm.deb
Size/MD5 checksum: 197342 11591d7d943ee2d38f0117b53ec59026
krb5-clients_1.2.4-5woody8_arm.deb
Size/MD5 checksum: 160678 f4118cf6266830f7db9553329dcc1532
krb5-ftpd_1.2.4-5woody8_arm.deb
Size/MD5 checksum: 48830 dc4986db69fc9fa3aacd9487a1a57004
krb5-kdc_1.2.4-5woody8_arm.deb
Size/MD5 checksum: 198672 6e11c792134a4d9bd602a7461895c42c
krb5-rsh-server_1.2.4-5woody8_arm.deb
Size/MD5 checksum: 63738 01cee2e685f3bc973f7cce7e5ec08f56
krb5-telnetd_1.2.4-5woody8_arm.deb
Size/MD5 checksum: 49406 03755be7fa950f05c099aff6dc847e7d
krb5-user_1.2.4-5woody8_arm.deb
Size/MD5 checksum: 166018 b8000d9c82076d7134aacf28a3ae7a98
libkadm55_1.2.4-5woody8_arm.deb
Size/MD5 checksum: 73626 3070b54d29b8174b78886e37bc25c112
libkrb5-dev_1.2.4-5woody8_arm.deb
Size/MD5 checksum: 493632 b74a2e03c250019f25ff58387792d666
libkrb53_1.2.4-5woody8_arm.deb
Size/MD5 checksum: 295230 bd4ccc64814aeebd0071b68dc964080d

Intel IA-32 architecture:

krb5-admin-server_1.2.4-5woody8_i386.deb
Size/MD5 checksum: 179362 e38dffa6b1e44da9c05ab5569283141b
krb5-clients_1.2.4-5woody8_i386.deb
Size/MD5 checksum: 152348 eb2d37aca6f5aeb2ecd3dc7a66b351fc
krb5-ftpd_1.2.4-5woody8_i386.deb
Size/MD5 checksum: 46370 dda52cc0f381955716025f4f3f210630
krb5-kdc_1.2.4-5woody8_i386.deb
Size/MD5 checksum: 178578 3d9e28bc8bbd83161cd8c9781db99e76
krb5-rsh-server_1.2.4-5woody8_i386.deb
Size/MD5 checksum: 61358 846936ed49d43dddf11c8239e7ecb74f
krb5-telnetd_1.2.4-5woody8_i386.deb
Size/MD5 checksum: 46652 4b12ff1ef17b81aadec2cf27c249b263
krb5-user_1.2.4-5woody8_i386.deb
Size/MD5 checksum: 156624 2a626d8694742a825242085d83efb40f
libkadm55_1.2.4-5woody8_i386.deb
Size/MD5 checksum: 72022 678e924f12886c54cb3ca9bdee6a8da4
libkrb5-dev_1.2.4-5woody8_i386.deb
Size/MD5 checksum: 433960 9a90e0a4c79b81f2d00945fb7bdf84da
libkrb53_1.2.4-5woody8_i386.deb
Size/MD5 checksum: 293706 be17bc6de25438a34466e7a47c5e4a0f

Intel IA-64 architecture:

krb5-admin-server_1.2.4-5woody8_ia64.deb
Size/MD5 checksum: 322390 bd8deae9fe5e2fd0d0e304d93c676c95
krb5-clients_1.2.4-5woody8_ia64.deb
Size/MD5 checksum: 266614 fa5fedbcc5ce19cf0fd6e0f019988aaa
krb5-ftpd_1.2.4-5woody8_ia64.deb
Size/MD5 checksum: 73742 3b21c0fd054d80e979808c47bef49b15
krb5-kdc_1.2.4-5woody8_ia64.deb
Size/MD5 checksum: 322348 b893958f43de292d927b49cd9dda434b
krb5-rsh-server_1.2.4-5woody8_ia64.deb
Size/MD5 checksum: 92050 2c1a3cf4ae7311dc95a696bf919148e9
krb5-telnetd_1.2.4-5woody8_ia64.deb
Size/MD5 checksum: 70700 38b66040685eb5421abcb92cdcb682df
krb5-user_1.2.4-5woody8_ia64.deb
Size/MD5 checksum: 256278 5440c691dcc69e168105b60a4433332d
libkadm55_1.2.4-5woody8_ia64.deb
Size/MD5 checksum: 107650 0b12f0212a2e8ee31654a605e7b74219
libkrb5-dev_1.2.4-5woody8_ia64.deb
Size/MD5 checksum: 705942 9dc21d18876a435f5ecbae3c1fa90fac
libkrb53_1.2.4-5woody8_ia64.deb
Size/MD5 checksum: 475034 072e1682115dd9c556d2eca5c65780af

HP Precision architecture:

krb5-admin-server_1.2.4-5woody8_hppa.deb
Size/MD5 checksum: 214666 50a69b51ec610a919c00e13dad97c237
krb5-clients_1.2.4-5woody8_hppa.deb
Size/MD5 checksum: 189950 ed974a7360091fe4ea8a5dee5f310a93
krb5-ftpd_1.2.4-5woody8_hppa.deb
Size/MD5 checksum: 54064 87d03aa246e3a8bed874ea20aab5c90c
krb5-kdc_1.2.4-5woody8_hppa.deb
Size/MD5 checksum: 214092 fdb3544036609131e218f1293d59ab62
krb5-rsh-server_1.2.4-5woody8_hppa.deb
Size/MD5 checksum: 68802 6476e62e8872de28da85a6d7ff6a91a8
krb5-telnetd_1.2.4-5woody8_hppa.deb
Size/MD5 checksum: 55892 ae903fa8671838a64061748b150503ae
krb5-user_1.2.4-5woody8_hppa.deb
Size/MD5 checksum: 183066 bde3354927006d85aed74b4ce67f379b
libkadm55_1.2.4-5woody8_hppa.deb
Size/MD5 checksum: 85122 160ea9c72f59ee814853092ba414f37e
libkrb5-dev_1.2.4-5woody8_hppa.deb
Size/MD5 checksum: 558094 4b5f91e312a31a075cf0ee5f5abb28f4
libkrb53_1.2.4-5woody8_hppa.deb
Size/MD5 checksum: 362152 bf33b679c8e3023f1baa81dedc1c9e32

Motorola 680x0 architecture:

krb5-admin-server_1.2.4-5woody8_m68k.deb
Size/MD5 checksum: 164376 695f5090f6f02ef5ffcdb94994923d1d
krb5-clients_1.2.4-5woody8_m68k.deb
Size/MD5 checksum: 144904 f03b67ac31422c20cd2024a7f530f077
krb5-ftpd_1.2.4-5woody8_m68k.deb
Size/MD5 checksum: 44522 7bb04f7623ecb06934e615790364744e
krb5-kdc_1.2.4-5woody8_m68k.deb
Size/MD5 checksum: 164106 460978cf8ba185277681491f91269bd3
krb5-rsh-server_1.2.4-5woody8_m68k.deb
Size/MD5 checksum: 57054 8bcee8e9061c204cc1d53f310603f647
krb5-telnetd_1.2.4-5woody8_m68k.deb
Size/MD5 checksum: 44838 c57524e8c13e8f007451617b6c99374f
krb5-user_1.2.4-5woody8_m68k.deb
Size/MD5 checksum: 146184 ef14d19fd5d0d4bb4a4ee88287e556cd
libkadm55_1.2.4-5woody8_m68k.deb
Size/MD5 checksum: 70032 1bccace886d6c662ab3b10b0cfaa29d9
libkrb5-dev_1.2.4-5woody8_m68k.deb
Size/MD5 checksum: 409054 be8e8f2a4573bb15ec6024f00a1c4087
libkrb53_1.2.4-5woody8_m68k.deb
Size/MD5 checksum: 277330 c78d56b08e2e4c37bc7d9d1aae9272f6

Big endian MIPS architecture:

krb5-admin-server_1.2.4-5woody8_mips.deb
Size/MD5 checksum: 206742 9881404c18f586f88b60322f6ac46e11
krb5-clients_1.2.4-5woody8_mips.deb
Size/MD5 checksum: 191334 637743e42bdcbd990a8a8eaec03f04e6
krb5-ftpd_1.2.4-5woody8_mips.deb
Size/MD5 checksum: 53510 c194be0f6dedfbaa82f3f7f51bbafe48
krb5-kdc_1.2.4-5woody8_mips.deb
Size/MD5 checksum: 209794 7ad1a3ae1a623910446a89d44f4d7c0a
krb5-rsh-server_1.2.4-5woody8_mips.deb
Size/MD5 checksum: 66606 0921f3d4930ad9501eba05cb48c86093
krb5-telnetd_1.2.4-5woody8_mips.deb
Size/MD5 checksum: 55072 22603859834a0c66169b9c6b3438296b
krb5-user_1.2.4-5woody8_mips.deb
Size/MD5 checksum: 175416 edcbd96200fec2b725a64df310856287
libkadm55_1.2.4-5woody8_mips.deb
Size/MD5 checksum: 72292 afa180a53f462b42ada57f4183e481b2
libkrb5-dev_1.2.4-5woody8_mips.deb
Size/MD5 checksum: 541350 be00fa435c03a2474310c03b3aadb3d0
libkrb53_1.2.4-5woody8_mips.deb
Size/MD5 checksum: 308518 db69345f0ad3df1e0b3b70310ffa6ed6

Little endian MIPS architecture:

krb5-admin-server_1.2.4-5woody8_mipsel.deb
Size/MD5 checksum: 210850 d7831efe581155af02fbf4cd4b298577
krb5-clients_1.2.4-5woody8_mipsel.deb
Size/MD5 checksum: 190990 facf8459bd0684335304e2a9af7b8ec1
krb5-ftpd_1.2.4-5woody8_mipsel.deb
Size/MD5 checksum: 53694 cbae172d0491dd9f259b31f502d3f0ef
krb5-kdc_1.2.4-5woody8_mipsel.deb
Size/MD5 checksum: 213350 9b2e3742c660d42556e790503cfa73c2
krb5-rsh-server_1.2.4-5woody8_mipsel.deb
Size/MD5 checksum: 66918 cf9b408405283ea6cda2dc7d79dc5187
krb5-telnetd_1.2.4-5woody8_mipsel.deb
Size/MD5 checksum: 54936 13d0e562fea89e39cecffe02caa5184f
krb5-user_1.2.4-5woody8_mipsel.deb
Size/MD5 checksum: 177270 6e92b594956acc65452e8c351222fb53
libkadm55_1.2.4-5woody8_mipsel.deb
Size/MD5 checksum: 72106 54a3fbae7e86134d48ee49befcb00c99
libkrb5-dev_1.2.4-5woody8_mipsel.deb
Size/MD5 checksum: 540884 a93fd74e3cfce1d61e81dc15adeede7d
libkrb53_1.2.4-5woody8_mipsel.deb
Size/MD5 checksum: 307184 e725f0ab101cf33b1eb127eb3d18df81

PowerPC architecture:

krb5-admin-server_1.2.4-5woody8_powerpc.deb
Size/MD5 checksum: 188456 1605cd80b08025be71477d33bae41d53
krb5-clients_1.2.4-5woody8_powerpc.deb
Size/MD5 checksum: 164152 0e3d09352a72b78dce03519b297a87c3
krb5-ftpd_1.2.4-5woody8_powerpc.deb
Size/MD5 checksum: 49372 9289fc6a3d9a4a1e35e55a8f536b2762
krb5-kdc_1.2.4-5woody8_powerpc.deb
Size/MD5 checksum: 189546 cee053d38c1f38de08966f6957ed914a
krb5-rsh-server_1.2.4-5woody8_powerpc.deb
Size/MD5 checksum: 62728 e6f98290ed591d955d5c80eb58d9f6dd
krb5-telnetd_1.2.4-5woody8_powerpc.deb
Size/MD5 checksum: 49338 bf451f9b226dd16dac16ee9c59d97783
krb5-user_1.2.4-5woody8_powerpc.deb
Size/MD5 checksum: 162762 2edc9dee6e7672c838626cd391820de9
libkadm55_1.2.4-5woody8_powerpc.deb
Size/MD5 checksum: 74060 5c6ce5c10f005fa31786354fd60c4616
libkrb5-dev_1.2.4-5woody8_powerpc.deb
Size/MD5 checksum: 490920 1a5ee5de494c46f5c00598b2ef5dff3d
libkrb53_1.2.4-5woody8_powerpc.deb
Size/MD5 checksum: 303574 0972361a36370e77050b37e46aeaed66

IBM S/390 architecture:

krb5-admin-server_1.2.4-5woody8_s390.deb
Size/MD5 checksum: 189308 1b5d39163a97cb6ea829810afb1a648c
krb5-clients_1.2.4-5woody8_s390.deb
Size/MD5 checksum: 166440 0709eaf98f958d5190afbe956a277995
krb5-ftpd_1.2.4-5woody8_s390.deb
Size/MD5 checksum: 50302 f8721e09d7b159a5e16b293a8999d43c
krb5-kdc_1.2.4-5woody8_s390.deb
Size/MD5 checksum: 190628 cd1c66f7eaa63239aee8fbb4a26bed76
krb5-rsh-server_1.2.4-5woody8_s390.deb
Size/MD5 checksum: 67096 a191f8826271cfe94a8aef0d8e6aece1
krb5-telnetd_1.2.4-5woody8_s390.deb
Size/MD5 checksum: 50278 b0fccd0d25256f8357e8f32e815bf6f6
krb5-user_1.2.4-5woody8_s390.deb
Size/MD5 checksum: 164334 ce022c07d1815b0df8b5f9a46e8c2ed8
libkadm55_1.2.4-5woody8_s390.deb
Size/MD5 checksum: 76638 4aa46656e9c0293fb5e28e56391e77bc
libkrb5-dev_1.2.4-5woody8_s390.deb
Size/MD5 checksum: 453482 b52bf2d4a664c52c350f80c1593ea5c2
libkrb53_1.2.4-5woody8_s390.deb
Size/MD5 checksum: 319656 7b7d0c4b136d99b9dfaf798d4f94d0c9

Sun Sparc architecture:

krb5-admin-server_1.2.4-5woody8_sparc.deb
Size/MD5 checksum: 183454 aa907094cbdaac57da2f0eca9b8eb5bd
krb5-clients_1.2.4-5woody8_sparc.deb
Size/MD5 checksum: 173036 7f173f3267bcab3e66922ea6d40b9108
krb5-ftpd_1.2.4-5woody8_sparc.deb
Size/MD5 checksum: 49792 ce46cc950c54a24025647cec765c6e6b
krb5-kdc_1.2.4-5woody8_sparc.deb
Size/MD5 checksum: 184358 1ae257a74f7e385a2e4e186a26e86da6
krb5-rsh-server_1.2.4-5woody8_sparc.deb
Size/MD5 checksum: 64400 6429cb02f6d8c3948ef94176ee077c9e
krb5-telnetd_1.2.4-5woody8_sparc.deb
Size/MD5 checksum: 49780 dc7690038fd1b4125179157411f96396
krb5-user_1.2.4-5woody8_sparc.deb
Size/MD5 checksum: 159528 4c9938799737182f5fd4455f7ba08508
libkadm55_1.2.4-5woody8_sparc.deb
Size/MD5 checksum: 73406 83f33192e1d069af16c155136117b331
libkrb5-dev_1.2.4-5woody8_sparc.deb
Size/MD5 checksum: 463024 94916989bafb9975e1d973cc0210b1d0
libkrb53_1.2.4-5woody8_sparc.deb
Size/MD5 checksum: 301464 ebf61bee3343e02ea2d64066a6713424


These files will probably be moved into the stable distribution on
its next update.

--------------------------------------------------------------------------------
-
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-securitydists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)

iD8DBQFCTXAvW5ql+IAeqTIRAuL+AKCET+ogp0mdHV6KfcZ+HmunHGZBRwCfeUgI
8w9yUaCYB2+gRUK/2mZkGxU=
=L3X1
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact
listmaster@lists.debian.org
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung