USN-940-2: Kerberos vulnerability

21 July 2010

krb5 vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 10.04 LTS

Summary

An attacker could send crafted input to kadmind and cause it to crash.

Software Description

  • krb5 - MIT Kerberos

Details

USN-940-1 fixed vulnerabilities in Kerberos. This update provides the corresponding updates for Ubuntu 10.04.

Original advisory details:

Joel Johnson, Brian Almeida, and Shawn Emery discovered that Kerberos did not correctly verify certain packet structures. An unauthenticated remote attacker could send specially crafted traffic to cause the KDC or kadmind services to crash, leading to a denial of service. (CVE-2010-1320, CVE-2010-1321)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 10.04 LTS
krb5-admin-server - 1.8.1+dfsg-2ubuntu0.2

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References