|
|||||||||||
|
patches available for the Kerberos v4 protocol bug
From: Todd C. Miller <Todd.Miller(at)courtesan.com>
Date: Mon Mar 24 2003 - 14:28:28 EST
Kerberos v5 does not have this weakness, but since it contains v4 to v5 translation services it is still possible to exploit the v4 protocol defect. For more information, please see: http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt The following patches cause Kerberos v4 requests from foreign realms to be ignored unless support for this is explicitly enabled. Patch for OpenBSD 3.1: ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/026_kerberos.patch Patch for OpenBSD 3.2: ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/013_kerberos.patch The aforementioned patches have already been applied to the 3.1 and 3.2 -stable branches. Received on Mon Mar 24 14:31:40 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:46:07 EDT |
||||||||||
|
|||||||||||