[Technik] [SECURITY] [DSA 1367-2] New krb5 packages fix arbitrary code execution

Noèl Köthe noel at debian.org
Mon Sep 10 10:03:25 CEST 2007


Am Donnerstag, den 06.09.2007, 23:25 +0200 schrieb Moritz Muehlenhoff:

> Debian Security Advisory DSA 1367-2                    security at debian.org
> http://www.debian.org/security/                         Moritz Muehlenhoff
> September 6th, 2007                     http://www.debian.org/security/faq
> 
> Package        : krb5
> Vulnerability  : buffer overflow
> Problem-Type   : remote
> Debian-specific: no
> CVE ID         : CVE-2007-3999

krb5 auf cree und yuma aktualisiert.

> For the stable distribution (etch) this problem has been fixed in
> version 1.4.4-7etch4.

changelog:
krb5 (1.4.4-7etch4) stable-security; urgency=emergency

  * Fix bug in fix for CVE-2007-3999: the previous patch could allow an
    overflow of up to 32 bytes.   Depending on how locals are layed out on
    the stack, this may or may not be a problem.

 -- Sam Hartman <hartmans at debian.org>  Tue, 04 Sep 2007 19:51:49 -0400

krb5 (1.4.4-7etch3) stable-security; urgency=emergency

  * Fix for mit-sa-2007-06  (in particular cve-2007-3999) : stack buffer
    overflow in rpcsec_gss when parsing rpchdr 

 -- Sam Hartman <hartmans at debian.org>  Sat, 25 Aug 2007 16:39:24 -0400

-- 
Noèl Köthe <noel debian.org>
Debian GNU/Linux, www.debian.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Dies ist ein digital signierter Nachrichtenteil
Url : /archiv/technik/attachments/20070910/4c08603d/attachment.pgp


More information about the Technik mailing list