|
|
Subscribe / Log in / New account

Debian alert DLA-2166-1 (libpam-krb5)

From:  Utkarsh Gupta <utkarsh@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2166-1] libpam-krb5 security update
Date:  Wed, 1 Apr 2020 20:13:52 +0530
Message-ID:  <7db8d257-9b13-67a4-27ad-a3bff3cea971@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Package : libpam-krb5 Version : 4.6-3+deb8u1 CVE ID : CVE-2020-10595 The krb5 PAM module (pam_krb5.so) had a buffer overflow that might have caused remote code execution in situations involving supplemental prompting by a Kerberos library. It might have overflown a buffer provided by the underlying Kerberos library by a single '\0' byte if an attacker responded to a prompt with an answer of a carefully chosen length. The effect may have ranged from heap corruption to stack corruption depending on the structure of the underlying Kerberos library, with unknown effects but possibly including code execution. This code path had not been used for normal authentication, but only when the Kerberos library did supplemental prompting, such as with PKINIT or when using the non-standard no_prompt PAM configuration option. For Debian 8 "Jessie", this problem has been fixed in version 4.6-3+deb8u1. The fix was prepared by Mike Gabriel. We recommend that you upgrade your libpam-krb5 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Best, Utkarsh -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl6EqKQACgkQgj6WdgbD S5aLiA/+MBaSnqC8rGDxGYlVOzm0mVHOE+hF3Sd7epmbFoskIxHoFZFEh3vmu4we u87Ckgaat2S3Wq/F83mTdLDI/q0Y7PAoHebUoeolv3G4BRkwcGvdUq8hqiRbiwca 3eedyno1hOOWo8ZWZ45+3weF0OSpViuousuNZ9cutBWNY7OYkRVMRt7xR+95Axv+ IdSS//5GasHQx5B13WSxI0wKvZFSAar132lmhbVL/wTvdE7BBy1J5pQ1mMHQ3IHy ZidvjpKwfs73s5ONqcjnWcMQfNu6lgMQwv8sIDphCjRrb+oxfjCbL+gwdtVMAIlq U9gsPZ687iJzvCfAexUBk9kSmQf/u9mlEPh0DFmSVAfCWCQeXwCgQBGTDrib6ZR2 v48A/k50UIBURMpmwXn3QeymgU5H6j4838YJF8740wmzX+QbkfwlxSqiJ9M+B7+x 7QaLNNNSBXQUgat+B3e5hQf5JSC8FAPqMALJWSprPNoVRC+LaEO1Uhb3UMrWxcbP irLvt2hays8z+n1zgqDfMMxpuSHiSwa4m+wZrrUsJSwqtxoq1MrmqRGUOOTbIKHY w/i18YLqHqJ8osiM27vhCg3mbizXx3Jgjc+A4RLAq+9sL6HG2ARDVQ0K6LJ638yy m81EdLCk8TbXFBeAiSdVlbXgiNXANuScOqRyWB+Ww13b0GX24jY= =ff5P -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds