J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1545
    posted: 11/19/09
  • NSM Daily Update #1545
    posted: 11/19/09
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1545
    posted: 11/19/09
  • Deep Inspection 5.1 and 5.2 #1435
    posted: 11/19/09
  • Deep Inspection 5.0, 5.3r4 and below #1132
    posted: 03/28/08 (04/01/08 for 5.0)
  • Antivirus
    posted: 11/19/09

Title: MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability

Severity: CRITICAL

Description:

MIT Kerberos 5 is a suite of applications and libraries designed to implement the Kerberos network-authentication protocol. It is freely available and operates on numerous platforms.

MIT Kerberos 5 is prone to a remote code-execution vulnerability. This issue resides in the server-side portion of the Kerberos RPC library. Currently, the 'kadmind' service is known to be vulnerable, but other applications that use this library may also be affected. Specifically, the 'SVCAUTH_DESTROY()' function uses a pointer in the 'SVCAUTH' structure that points to previously freed memory. This may potentially allow attackers to control the pointer to facilitate the execution of arbitrary machine code in the context of affected applications.

An attacker can exploit this issue to execute arbitrary code with administrative privileges, completely compromising affected computers. Failed exploit attempts will result in a denial of service. After a Kerberos database computer has been compromised, attackers may gain unauthorized access to
other services that rely on the Kerberos infrastructure for authentication.

Affected Products:

  • Apple Mac OS X 10.4.9
  • Apple Mac OS X Server 10.4.9
  • Gentoo Linux
  • MIT Kerberos 5 1.4.0
  • MIT Kerberos 5 1.4.1
  • MIT Kerberos 5 1.4.2
  • MIT Kerberos 5 1.4.3
  • MIT Kerberos 5 1.5.0
  • MIT Kerberos 5 1.5.1
  • MandrakeSoft Corporate Server 4.0
  • MandrakeSoft Corporate Server 4.0.0 x86_64
  • MandrakeSoft Linux Mandrake 2006.0.0
  • MandrakeSoft Linux Mandrake 2006.0.0 x86_64
  • MandrakeSoft Linux Mandrake 2007.0
  • MandrakeSoft Linux Mandrake 2007.0 x86_64
  • OpenPKG OpenPKG 2-Stable-20061018
  • OpenPKG OpenPKG Current
  • OpenPKG OpenPKG E1.0-Solid
  • OpenPKG OpenPKG Stable
  • SuSE Linux 10.0
  • SuSE Linux 10.1
  • SuSE Linux 9.3
  • SuSE SLED 10.0
  • SuSE SLES 10
  • Trustix Operating System Enterprise Server 2.0
  • Trustix Secure Linux 2.2.0
  • Trustix Secure Linux 3.0.0
  • Ubuntu Ubuntu Linux 6.06 LTS amd64
  • Ubuntu Ubuntu Linux 6.06 LTS i386
  • Ubuntu Ubuntu Linux 6.06 LTS powerpc
  • Ubuntu Ubuntu Linux 6.06 LTS sparc
  • Ubuntu Ubuntu Linux 6.10 amd64
  • Ubuntu Ubuntu Linux 6.10 i386
  • Ubuntu Ubuntu Linux 6.10 powerpc
  • Ubuntu Ubuntu Linux 6.10 sparc
  • rPath rPath Linux 1

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.