|
MIT Kerberos 5 KRB5_AName_To_Localname Multiple Principal Name Buffer Overrun Vulnerabilities
Solution: This issue has been addressed in krb5-1.3.4. Trustix has released an advisory (TSLSA-2004-0032) and fixes to address this issue in Trustix products. Users of the SWUP tool may apply these updates using 'swup --upgrade'. Customers are advised to see the referenced advisory for further details regarding obtaining and applying appropriate fixes. Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information. Tinysofa has released advisory TSSA-2004-009 along with fixes dealing with this issue. Please see the advisory in web references for further details. MIT has released an update to advisory MITKRB5-SA-2004-001 as well as fixes dealing with this issue. Please see the referenced advisory for more information. Mandrake has released advisory MDKSA-2004:056 and fixes dealing with this issue. Please see the referenced advisory for more information. RedHat has released advisories FEDORA-2004-149 and FEDORA-2004-150 to address these issues in Fedora Core 1 and Fedora Core 2. Please see the referenced advisories for more information. Red Hat has released advisory RHSA-2004:236-14 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information. Mandrake Linux has released advisory MDKSA-2004:056-1 and fixes dealing with this issue. Please see the refereneced advisory for more information. This advisory is an update to MDKSA-2004:056, containing a bugfix for a problem contained in the previous packages. Sun has released security bulletin 57580 addressing this issue in Solaris and SEAM. Please refer to the Sun bulletin for further information. T patches are available through the vendors support system. Patches T-112237-11 and T-112390-09 are available for Solaris 8 on the SPARC platform. T-112240-08 and T-112238-10 are available for Solaris 8 on the x86 platform. Debian has released advisory DSA 520-1 with fixes that address these issues. Please see the referenced advisory for more information. Trustix has released advisory TSL-2004-0036 to address this issue. Please see the attached advisory for details on obtaining and applying fixes. SGI has released a security advisory (20040604-01-U) to address this and other issues in SGI ProPack 3. Please see the referenced advisory for more information. SGI has released a security advisory (20040605-01-U) to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information. Gentoo Linux has released advisory GLSA 200406-21 dealing with this issue. Please see the referenced Gentoo advisory for more information. They have recommended that all mit-krb5 users should upgrade to the latest version using the following sequence of commands: emerge sync emerge -pv ">=app-crypt/mit-krb5-1.3.3-r1" emerge ">=app-crypt/mit-krb5-1.3.3-r1" Conectiva has made advisory CLSA-2004:860 along with fixes available resolving this and other issues. Please see the referenced advisory for more information. Sun has released an update to their security bulletin 57580. The Solaris 9 patch for the SPARC architecture is now available again. Please see the referenced advisory. Sun has released patches for their Solaris 8 product. Users should be advised that for both the SPARC and x86 platform both patches must be applied to resolve this issue. Please see the referenced advisory for more information. Fedora Legacy has released security advisory FLSA:154276 addressing this issue for RedHat Linux 7.3 and 9, and for Fedora Core 1. Please see the referenced advisory for details on obtaining and applying the appropriate updates. Sun Solaris 8 Sun Solaris 9 Sun Solaris 9_x86 Sun Solaris 8_x86
Sun SEAM 1.0
MIT Kerberos 5 1.0
MIT Kerberos 5 1.0.6
MIT Kerberos 5 1.0.8
MIT Kerberos 5 1.1
MIT Kerberos 5 1.1.1
MIT Kerberos 5 1.2
MIT Kerberos 5 1.2.1
MIT Kerberos 5 1.2.2
MIT Kerberos 5 1.2.2 -beta1
MIT Kerberos 5 1.2.3
MIT Kerberos 5 1.2.4
MIT Kerberos 5 1.2.5
MIT Kerberos 5 1.2.6
MIT Kerberos 5 1.2.7
MIT Kerberos 5 1.3
MIT Kerberos 5 1.3 -alpha1
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X 10.3.4
Apple Mac OS X Server 10.3.4
Apple Mac OS X Server 10.3.5
Apple Mac OS X 10.3.5
SGI ProPack 2.4
SGI ProPack 3.0
MIT Kerberos 5 5.0 -1.2beta1
MIT Kerberos 5 5.0 -1.1
MIT Kerberos 5 5.0 -1.2beta2
MIT Kerberos 5 5.0 -1.0.x
MIT Kerberos 5 5.0 -1.3.3
MIT Kerberos 5 5.0 -1.1.1
|
|
|
Privacy Statement |