The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


FLEA-2007-0008-1: krb5


<< Previous INDEX Search src / Print Next >>
Date: Thu, 05 Apr 2007 14:52:50 -0400
From: Foresight Linux Essential Announcement Service <foresight-security-noreply@foresightlinux.org.>
To: foresight-security-announce@lists.rpath.org
Subject: FLEA-2007-0008-1: krb5
References: <45EF374E.1090207@foresightlinux.org.> <45EF8D85.3050102@moritz-naumann.com.>
In-Reply-To: <45EF8D85.3050102@moritz-naumann.com.>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: antivirus-gw at tyumen.ru

Foresight Linux Essential Advisory: 2007-0008-1
Published: 2007-04-05

Rating: Informational

Updated Versions:
     krb5=/conary.rpath.com@rpl:devel//1/1.4.1-7.6-1
     krb5-server=/conary.rpath.com@rpl:devel//1/1.4.1-7.6-1
     krb5-services=/conary.rpath.com@rpl:devel//1/1.4.1-7.6-1
     krb5-test=/conary.rpath.com@rpl:devel//1/1.4.1-7.6-1
     krb5-workstation=/conary.rpath.com@rpl:devel//1/1.4.1-7.6-1
     group-dist=/foresight.rpath.org@fl:1-devel//1/1.1-0.13-2

References:
     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0956
     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0957
     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1216
     https://issues.rpath.com/browse/RPL-1212

Description:
     Previous versions of the krb5 package are vulnerable to three attacks that 
can be triggered remotely, one of which is known to provide unauthenticated 
unrestricted shell access to any system running the krb5 telnet daemon. 
Foresight Linux proper is not vulnerable to these attacks, since krb5-server is 
not included in Foresight.



<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру