Description: | Description: The remote host is missing an update to krb5 announced via advisory FEDORA-2011-1225.
Update Information:
This update incorporates fixes from upstream advisories MITKRB5-SA-2011-001 (standalone kpropd exits if a per-client child exits with an error) and MITKRB5-SA-2011-002 (uninitialized pointer crash in the KDC, hang or crash in the KDC with the LDAP backend).
References:
[ 1 ] Bug #664009 - CVE-2010-4022 krb5: kpropd unexpected termination on invalid input (MITKRB5-SA-2011-001) https://bugzilla.redhat.com/show_bug.cgi?id=664009 [ 2 ] Bug #668719 - CVE-2011-0281 krb5: KDC hang when using LDAP backend caused by special principal name (MITKRB5-SA-2011-002) https://bugzilla.redhat.com/show_bug.cgi?id=668719 [ 3 ] Bug #668726 - CVE-2011-0282 krb5: KDC crash when using LDAP backend caused by a special principal name (MITKRB5-SA-2011-002) https://bugzilla.redhat.com/show_bug.cgi?id=668726
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update krb5' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2011-1225
Risk factor : Medium
CVSS Score: 5.0
|