DSA-1969-1 krb5 -- integer underflowID: oval:org.secpod.oval:def:600118 | Date: (C)2011-01-28 (M)2022-10-10 |
Class: PATCH | Family: unix |
It was discovered that krb5, a system for authenticating users and services on a network, is prone to integer underflow in the AES and RC4 decryption operations of the crypto library. A remote attacker can cause crashes, heap corruption, or, under extraordinarily unlikely conditions, arbitrary code execution. For the old stable distribution , this problem has been fixed in version 1.4.4-7etch8. For the stable distribution , this problem has been fixed in version 1.6.dfsg.4~beta1-5lenny2. For the testing distribution , this problem will be fixed soon. For the unstable distribution , this problem has been fixed in version 1.8+dfsg~alpha1-1. We recommend that you upgrade your krb5 package.
Platform: |
Debian 5.0 |
Debian 4.0 |