Release date:
Updated on:
Affected Systems:
Debian Linux 5.0 x
MIT Kerberos 5 <5-1.9
RedHat Linux
Description:
--------------------------------------------------------------------------------
Bugtraq id: 47310
Cve id: CVE-2011-0285
Kerberos is a network authentication protocol designed to provide powerful authentication services for client/server applications through the key system.
The MIT Kerberos kadmind password change feature has a remote code execution vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary code with the superuser permission, causing the affected applications to crash or DoS legitimate users.
<* Source: Felipe Ortega
Link: http://bugs.debian.org/cgi-bin/bugreport.cgi? Bug = 621726
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
# Nmap-n-sV krb01
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MIT
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://web.mit.edu/kerberos/www/advisories/index.html