Personal tools
     DOCUMENTATION

Advisories:rPSA-2008-0112

From rPath Wiki

Jump to: navigation, search

rPath Security Advisory 2008-0112-2

Published: 2008-03-19

Updated

  1. 2008-03-20 lower Rating to Severe, improve Description

Products

  • rPath Linux 1
  • rPath Appliance Platform Linux Service 1

Rating

Severe

Exposure Level Classification

Remote Root Deterministic Unauthorized Access

Updated Versions

  • krb5=conary.rpath.com@rpl:1/1.4.1-7.9-1
  • krb5-server=conary.rpath.com@rpl:1/1.4.1-7.9-1
  • krb5-services=conary.rpath.com@rpl:1/1.4.1-7.9-1
  • krb5-test=conary.rpath.com@rpl:1/1.4.1-7.9-1
  • krb5-workstation=conary.rpath.com@rpl:1/1.4.1-7.9-1

rPath Issue Tracking System

References

Description

Previous versions of the krb5 package contain multiple
vulnerabilities, the most serious of which may allow a
remote attacker to execute arbitrary code.
20 March 2008 Update: This unauthenticated remote Arbitrary Code
Execution attack is believed to be limited to the kadmind server.
rPath Linux systems are not automatically configured with kadmind
enabled; only systems configured as kerberos administrative servers
are vulnerable.
Other unrelated vulnerabilities include Denials of Service and
possible Information Exposures.

Copyright 2008 rPath, Inc. This file is distributed under the terms of the MIT License. A copy is available at http://www.rpath.com/permanent/mit-license.html