Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

patches available for the Kerberos v4 protocol bug

From: Todd C. Miller <Todd.Miller(at)courtesan.com>
Date: Mon Mar 24 2003 - 14:28:28 EST


There is a cryptographic weaknesses in the Kerberos v4 protocol (this is not something that is fixable in Kerberos v4). Sites still using Kerberos v4 should migrate to Kerberos v5.

Kerberos v5 does not have this weakness, but since it contains v4 to v5 translation services it is still possible to exploit the v4 protocol defect.

For more information, please see:

    http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt

The following patches cause Kerberos v4 requests from foreign realms to be ignored unless support for this is explicitly enabled.

Patch for OpenBSD 3.1:

    ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/026_kerberos.patch

Patch for OpenBSD 3.2:

Do you need help?X

    ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/013_kerberos.patch

The aforementioned patches have already been applied to the 3.1 and 3.2 -stable branches. Received on Mon Mar 24 14:31:40 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:46:07 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library