Package : krb5
Vulnerability : several
Problem-Type : remote
Debian-specific: no
CVE ID : CVE-2007-2442 CVE-2007-2443 CVE-2007-2798
Several remote vulnerabilities have been discovered in the MIT reference
implementation of the Kerberos network authentication protocol suite,
which may lead to the execution of arbitrary code. The Common
Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-2442
Wei Wang discovered that the free of an uninitialised pointer in the
Kerberos RPC library may lead to the execution of arbitrary code.
CVE-2007-2443
Wei Wang discovered that insufficient input sanitising in the
Kerberos RPC library may lead to the execution of arbitrary code.
CVE-2007-2798
It was discovered that a buffer overflow in the Kerberos
administration daemon may lead to the execution of arbitrary code.
For the old stable distribution (sarge) these problems have been fixed in
version 1.3.6-2sarge5. Packages for hppa, mips and powerpc are not yet
available. They will be provided later.
For the stable distribution (etch) these problems have been fixed in
version 1.4.4-7etch2. Packages for hppa and mips are not yet available.
They will be provided later.
For the unstable distribution (sid) these problems have been fixed in
version 1.6.dfsg.1-5.
These files will probably be moved into the stable distribution on
its next update.
---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGhBYUXm3vHE4uyloRAiiwAKCASsoAV6Ck5mJc0qX1yUy8Syv7vgCg2jvj
Z8QRbwbDr/IJp2iktT/Q0O8=
=Vj4F
-----END PGP SIGNATURE----- Received on Thu Jun 28 17:48:36 2007
This archive was generated by hypermail 2.1.8
: Thu Jun 28 2007 - 17:50:04 EDT