LWN.net Logo

krb5: arbitrary code execution

Package(s):krb5 CVE #(s):CVE-2011-0285
Created:April 15, 2011 Updated:April 26, 2011
Description: From the CVE entry:

The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.

Alerts:
Mandriva MDVSA-2011:077 2011-04-22
Ubuntu USN-1116-1 2011-04-19
SUSE SUSE-SR:2011:007 2011-04-19
openSUSE openSUSE-SU-2011:0348-1 2011-04-18
Red Hat RHSA-2011:0447-01 2011-04-14
Fedora FEDORA-2011-5343 2011-04-14
Fedora FEDORA-2011-5345 2011-04-14
Gentoo 201201-13 2012-01-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds