Short Name |
APP:KERBEROS:KRB5-DOS
|
Severity |
Medium
|
Recommended |
Yes
|
Category |
APP
|
Release Date |
2011/06/01
|
Update Number |
1929
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
APP: MIT Kerberos Denial of Service
This signature detects attempts to exploit a known vulnerability against MIT Kerberos. A successful attack can result in a denial-of-service condition.
Extended Description
MIT Kerberos is prone to a remote code-execution vulnerability in 'kadmind'.
An attacker may exploit this issue to execute arbitrary code with superuser privileges. Failed attempts will cause the affected application to crash, denying service to legitimate users. A successful exploit will completely compromise affected computers.
MIT Kerberos 5 1.7 and later are vulnerable.
NOTE (April 13, 2011): This BID was originally titled 'MIT Kerberos kadmind Version String Processing Remote Denial Of Service Vulnerability', but has been renamed to better reflect the nature of the issue.
Affected Products
- Debian Linux 5.0
- Debian Linux 5.0 Alpha
- Debian Linux 5.0 Amd64
- Debian Linux 5.0 Arm
- Debian Linux 5.0 Armel
- Debian Linux 5.0 Hppa
- Debian Linux 5.0 Ia-32
- Debian Linux 5.0 Ia-64
- Debian Linux 5.0 M68k
- Debian Linux 5.0 Mips
- Debian Linux 5.0 Mipsel
- Debian Linux 5.0 Powerpc
- Debian Linux 5.0 S/390
- Debian Linux 5.0 Sparc
- Gentoo Linux
- Mandriva Enterprise Server 5
- Mandriva Enterprise Server 5 X86 64
- Mandriva Linux Mandrake 2010.1
- Mandriva Linux Mandrake 2010.1 X86 64
- MIT Kerberos 5 1.7
- MIT Kerberos 5 1.7.1
- MIT Kerberos 5 1.7.2
- MIT Kerberos 5 1.8
- MIT Kerberos 5 1.8.1
- MIT Kerberos 5 1.8.2
- MIT Kerberos 5 1.8.3
- MIT Kerberos 5 1.8.4
- MIT Kerberos 5 1.9
- MIT Kerberos 5 5-1.7
- MIT Kerberos 5 5-1.7.1
- MIT Kerberos 5 5-1.8
- MIT Kerberos 5 5-1.8.1
- MIT Kerberos 5 5-1.8.2
- MIT Kerberos 5 5-1.8.3
- MIT Kerberos 5 5-1.9
- Red Hat Enterprise Linux Desktop 6
- Red Hat Enterprise Linux Desktop Optional 6
- Red Hat Enterprise Linux HPC Node 6
- Red Hat Enterprise Linux HPC Node Optional 6
- Red Hat Enterprise Linux Server 6
- Red Hat Enterprise Linux Workstation 6
- Red Hat Fedora 13
- Red Hat Fedora 14
- Red Hat Fedora 15
- SuSE openSUSE 11.2
- SuSE openSUSE 11.3
- SuSE openSUSE 11.4
- Ubuntu Ubuntu Linux 10.04 Amd64
- Ubuntu Ubuntu Linux 10.04 ARM
- Ubuntu Ubuntu Linux 10.04 I386
- Ubuntu Ubuntu Linux 10.04 LTS
- Ubuntu Ubuntu Linux 10.04 Powerpc
- Ubuntu Ubuntu Linux 10.04 Sparc
- Ubuntu Ubuntu Linux 10.10 amd64
- Ubuntu Ubuntu Linux 10.10 ARM
- Ubuntu Ubuntu Linux 10.10 i386
- Ubuntu Ubuntu Linux 10.10 powerpc
- Ubuntu Ubuntu Linux 9.10
- Ubuntu Ubuntu Linux 9.10 Amd64
- Ubuntu Ubuntu Linux 9.10 ARM
- Ubuntu Ubuntu Linux 9.10 I386
- Ubuntu Ubuntu Linux 9.10 Lpia
- Ubuntu Ubuntu Linux 9.10 Powerpc
- Ubuntu Ubuntu Linux 9.10 Sparc
References