Multiple Cryptographic Weaknesses in Kerberos 4 Protocol

Solution:
Debian has released fixes for Kerberos 4 and Heimdal packages (DSA 273-1, DSA 269-2). Links to the fixes can be found in the Debian advisories in the References section.

NetBSD has released an advisory (2003-006). NetBSD users are advised to upgrade systems via CVS or to disable all kerberos cross-realm functionality until an upgrade is complete. Further details are available in the referenced advisory.

OpenBSD has released patches which address this issue.

A patch for Kerberos 5 with the affected Kerberos 4 code included is available. This patch may be downloaded at http://web.mit.edu/kerberos/www/advisories/2003-004-krb4_patchkit.tar.gz. This patch is not for the Kerberos 4 standalone code.

The OpenAFS Project has released a patch that resolves this issue. Additionally, this problem will be fixed in the forthcoming 1.2.9 release.

Gentoo Linux has released advisory 200303-26, 200305-09, and also advisory 200303-28. Fixes available resolve issues in OpenAFS (200303-26), Heimdal (200305-09) and also Kerberos (200303-28). More information concerning upgrading vulnerable systems is available in the referenced advisories.

Conectiva has released a security advisory (CLA-2003:639) containing fixes which address this issue. Users are advised to upgrade as soon as possible.


MIT Kerberos 4 Protocol

Heimdal Heimdal 0.4 e


 

Privacy Statement
Copyright 2010, SecurityFocus