USN-881-1: Kerberos vulnerability

12 January 2010

krb5 vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 9.10
  • Ubuntu 9.04
  • Ubuntu 8.10
  • Ubuntu 8.04 LTS
  • Ubuntu 6.06 LTS

Software Description

  • krb5

Details

It was discovered that Kerberos did not correctly handle invalid AES blocks. An unauthenticated remote attacker could send specially crafted traffic that would crash the KDC service, leading to a denial of service, or possibly execute arbitrary code with root privileges.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 9.10
libk5crypto3 - 1.7dfsg~beta3-1ubuntu0.3
Ubuntu 9.04
libkrb53 - 1.6.dfsg.4~beta1-5ubuntu2.2
Ubuntu 8.10
libkrb53 - 1.6.dfsg.4~beta1-3ubuntu0.3
Ubuntu 8.04 LTS
libkrb53 - 1.6.dfsg.3~beta1-2ubuntu1.3
Ubuntu 6.06 LTS
libkrb53 - 1.4.3-5ubuntu0.10

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system upgrade is sufficient to effect the necessary changes.

References