News: Cexx forums, with volunteers dedicated to helping you remove malware and stay protected
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
May 18, 2013, 11:40:49
Pages: [1]   Go Down
  Print  
Topic: Kerberos vuln - update available  (Read 1083 times)
0 Members and 1 Guest are viewing this topic.
« on: April 13, 2009, 10:06:17 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7314



FYI...

Kerberos Security Advisories
- http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2009-001.txt
Last update: 2009-04-07
Topic: multiple vulnerabilities in SPNEGO, ASN.1 decoder
...The upcoming krb5-1.7 and krb5-1.6.4 releases will contain fixes for these vulnerabilities... (or) Apply the patch, available at:
http://web.mit.edu/kerberos/advisories/2009-001-patch.txt ...
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0844
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0845
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0847

- http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2009-002.txt
Last update: 2009-04-07
Topic: ASN.1 decoder
...This is an implementation vulnerability in MIT krb5, and is not a vulnerability in the Kerberos protocol... The upcoming krb5-1.7 and krb5-1.6.4 releases will contain fixes for
this vulnerability...  (or) patch is also available at:
http://web.mit.edu/kerberos/advisories/2009-002-patch.txt
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0846 CVSS Severity: 10.0 (HIGH)

- http://atlas.arbor.net/briefs/index#-2016235497
April 13, 2009 - "MIT Kerberos 5 (krb5) versions prior to 1.6.4 , which is the foundation for many commercial Kerberos implementations, is vulnerable to three separate issues..."

- http://secunia.com/advisories/34347/2/
Last Update: 2009-04-08
Critical: Highly critical
Impact: Exposure of sensitive information, DoS, System access
Where: From remote
Solution Status: Vendor Patch
Software: Kerberos 5.x
Solution: Apply patches.
http://web.mit.edu/kerberos/advisories/2009-001-patch.txt
http://web.mit.edu/kerberos/advisories/2009-002-patch.txt
Reportedly, the vulnerabilities will also be fixed in the upcoming 1.7 and 1.6.4 release versions...
- http://secunia.com/advisories/34734/2/
Release Date: 2009-04-16

 Exclamation
« Last Edit: December 30, 2009, 02:47:57 by AplusWebMaster » Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
« Reply #1 on: December 30, 2009, 02:48:49 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7314



FYI...

Kerberos vuln - update available
- http://secunia.com/advisories/37977/2/
Release Date: 2009-12-29
Critical: Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch
Software: Kerberos 5.x
Solution: Apply patch:
http://web.mit.edu/kerberos/advisories/2009-003-patch.txt
The vulnerability will also be fixed in the upcoming krb5-1.7.1...

- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3295
Last revised: 12/30/2009

- http://securitytracker.com/alerts/2009/Dec/1023392.html
Date: Dec 29 2009

 Exclamation
« Last Edit: December 30, 2009, 05:21:40 by AplusWebMaster » Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
 
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Page created in 0.296 seconds with 20 queries.