USN-881-1: Kerberos vulnerability
12 January 2010
krb5 vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 9.10
- Ubuntu 9.04
- Ubuntu 8.10
- Ubuntu 8.04 LTS
- Ubuntu 6.06 LTS
Software Description
- krb5
Details
It was discovered that Kerberos did not correctly handle invalid AES blocks. An unauthenticated remote attacker could send specially crafted traffic that would crash the KDC service, leading to a denial of service, or possibly execute arbitrary code with root privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
- Ubuntu 9.10
- libk5crypto3 - 1.7dfsg~beta3-1ubuntu0.3
- Ubuntu 9.04
- libkrb53 - 1.6.dfsg.4~beta1-5ubuntu2.2
- Ubuntu 8.10
- libkrb53 - 1.6.dfsg.4~beta1-3ubuntu0.3
- Ubuntu 8.04 LTS
- libkrb53 - 1.6.dfsg.3~beta1-2ubuntu1.3
- Ubuntu 6.06 LTS
- libkrb53 - 1.4.3-5ubuntu0.10
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system upgrade is sufficient to effect the necessary changes.