[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

USN-1062-1 -- krb5 vulnerabilities

ID: oval:org.secpod.oval:def:700228Date: (C)2011-02-18   (M)2021-09-11
Class: PATCHFamily: unix




Keiichi Mori discovered that the MIT krb5 KDC database propagation daemon is vulnerable to a denial of service attack due to improper logic when a worker child process exited because of invalid network input. This could only occur when kpropd is running in standalone mode; kpropd was not affected when running in incremental propagation mode or as an inetd server. This issue only affects Ubuntu 9.10, Ubuntu 10.04 LTS, and Ubuntu 10.10. Kevin Longfellow and others discovered that the MIT krb5 Key Distribution Center daemon is vulnerable to denial of service attacks when using an LDAP back end due to improper handling of network input

Platform:
Ubuntu 8.04
Ubuntu 10.10
Ubuntu 9.10
Ubuntu 10.04
Product:
krb5
Reference:
USN-1062-1
CVE-2010-4022
CVE-2011-0281
CVE-2011-0282
CVE    3
CVE-2011-0281
CVE-2011-0282
CVE-2010-4022
CPE    4
cpe:/o:ubuntu:ubuntu_linux:8.04
cpe:/o:ubuntu:ubuntu_linux:10.04
cpe:/o:ubuntu:ubuntu_linux:9.10
cpe:/o:ubuntu:ubuntu_linux:10.10
...

© SecPod Technologies