USN-253-1: heimdal vulnerability

18 February 2006

heimdal vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 5.10
  • Ubuntu 5.04
  • Ubuntu 4.10

Software Description

Details

A remote Denial of Service vulnerability was discovered in the heimdal implementation of the telnet daemon. A remote attacker could force the server to crash due to a NULL de-reference before the user logged in, resulting in inetd turning telnetd off because it forked too fast.

Please note that the heimdal-servers package is not officially supported in Ubuntu (it is in the ‘universe’ component of the archive). However, this affects you if you use a customized version built from the heimdal source package (which is supported).

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 5.10
heimdal-servers
Ubuntu 5.04
heimdal-servers
Ubuntu 4.10
heimdal-servers

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

References