Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 2052-1] New krb5 packages fix denial of service (1/5)

    From Thijs Kinkhorst@1:229/2 to All on Mon May 24 22:10:03 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2052-1 [email protected] http://www.debian.org/security/ Sebastien Delafond
    May 24, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : krb5
    Vulnerability : null pointer dereference
    Problem type : remote
    Debian-specific: no
    CVE Id : CVE-2010-1321
    Debian Bug : 582261

    Shawn Emery discovered that in MIT Kerberos 5 (krb5), a system for authenticating users and services on a network, a null pointer
    dereference flaw in the Generic Security Service Application Program
    Interface (GSS-API) library could allow an authenticated remote attacker
    to crash any server application using the GSS-API authentication
    mechanism, by sending a specially-crafted GSS-API token with a missing
    checksum field.

    For the stable distribution (lenny), this problem has been fixed in
    version 1.6.dfsg.4~beta1-5lenny4.

    For the testing distribution (squeeze), this problem has been fixed in
    version 1.8.1+dfsg-3.

    For the testing distribution (sid), this problem has been fixed in
    version 1.8.1+dfsg-3.

    We recommend that you upgrade your krb5 packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/k/krb5/krb5_1.6.dfsg.4~beta1-5lenny4.diff.gz
    Size/MD5 checksum: 848699 4e016d8242b7648424be814a39616645
    http://security.debian.org/pool/updates/main/k/krb5/krb5_1.6.dfsg.4~beta1-5lenny4.dsc
    Size/MD5 checksum: 1537 2ffe877c62a1e84a71bf40ca09b00891
    http://security.debian.org/pool/updates/main/k/krb5/krb5_1.6.dfsg.4~beta1.orig.tar.gz
    Size/MD5 checksum: 11647547 08d6ce311204803acbe878ef0bb23c71

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/k/krb5/krb5-doc_1.6.dfsg.4~beta1-5lenny4_all.deb
    Size/MD5 checksum: 2148970 487480f9dd90a66ea45b30a46bd469fb

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/k/krb5/libkrb5-dev_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 93212 39af1e2e97e56cc49e144c1510714fc1
    http://security.debian.org/pool/updates/main/k/krb5/krb5-ftpd_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 72460 230a24dd8ce8cd44189e30a2e3ab673a
    http://security.debian.org/pool/updates/main/k/krb5/krb5-telnetd_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 83604 dc98d768332fecb7450291ac613919ad
    http://security.debian.org/pool/updates/main/k/krb5/krb5-admin-server_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 98844 e79c997e74ed8b37d88083ef44bf4019
    http://security.debian.org/pool/updates/main/k/krb5/libkrb5-dbg_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 1351506 52aba27137ac8375581ebe2a8fe0c9a9
    http://security.debian.org/pool/updates/main/k/krb5/krb5-kdc_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 219044 9278116dedac51494b2476b7713c8953
    http://security.debian.org/pool/updates/main/k/krb5/krb5-clients_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 255506 302e849c061c362ab54cc15e37a5ec1c
    http://security.debian.org/pool/updates/main/k/krb5/krb5-kdc-ldap_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 112606 509d66ed7c568e29ea9f0648d12ff335
    http://security.debian.org/pool/updates/main/k/krb5/krb5-user_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 148342 0ec171235494b9d04cfccce4ff1722da
    http://security.debian.org/pool/updates/main/k/krb5/krb5-pkinit_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 69824 9e74ac0a6dce328f0e0eed2d2f1f3edf
    http://security.debian.org/pool/updates/main/k/krb5/libkrb53_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 538210 7a0d1c002a2ca3dbf57fcd8b39e72c5c
    http://security.debian.org/pool/updates/main/k/krb5/krb5-rsh-server_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 98750 4fe06b7cab12ac33c81b577d16d2e9e1
    http://security.debian.org/pool/updates/main/k/krb5/libkadm55_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 180172 4ddaa9248aca121f6ea580bdff323277

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/k/krb5/libkrb5-dev_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 93582 0b074640128865b73ac0cfa727bd1a43
    http://security.debian.org/pool/updates/main/k/krb5/krb5-ftpd_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 68556 577791b743c31dc3ea86ef40a96d0d65
    http://security.debian.org/pool/updates/main/k/krb5/krb5-admin-server_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 93382 0721c7634225f750b4cfd702b951f852
    http://security.debian.org/pool/updates/main/k/krb5/krb5-rsh-server_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 94502 4ce752f3cb116e862ea10a08baa73db8
    http://security.debian.org/pool/updates/main/k/krb5/krb5-user_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 145160 8ab460824d9017091cacde79fff0e644
    http://security.debian.org/pool/updates/main/k/krb5/krb5-kdc-ldap_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 108572 1738b16ba0f67dc7f0f9c6f006fc3e57
    http://security.debian.org/pool/updates/main/k/krb5/libkadm55_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 169816 1f2f7323645080fb7dd5a337ca90da16
    http://security.debian.org/pool/updates/main/k/krb5/libkrb53_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 519994 98d9b8a92a289a30e269cb9847a123a3
    http://security.debian.org/pool/updates/main/k/krb5/krb5-clients_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 239468 867c83a3b26cd166b975caa5f080c77d
    http://security.debian.org/pool/updates/main/k/krb5/libkrb5-dbg_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 1474888 8a42a73cff994ade51fe75666cb867df
    http://security.debian.org/pool/updates/main/k/krb5/krb5-kdc_1.6.dfsg.4~beta1-5lenny4_amd64.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • From Sebastien Delafond@1:229/2 to All on Mon May 24 21:50:02 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2052-1 [email protected] http://www.debian.org/security/ Sebastien Delafond
    May 24, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : krb5
    Vulnerability : null pointer dereference
    Problem type : remote
    Debian-specific: no
    CVE Id : CVE-2010-1321
    Debian Bug : 582261

    Shawn Emery discovered that in MIT Kerberos 5 (krb5), a system for authenticating users and services on a network, a null pointer
    dereference flaw in the Generic Security Service Application Program
    Interface (GSS-API) library could allow an authenticated remote attacker
    to crash any server application using the GSS-API authentication
    mechanism, by sending a specially-crafted GSS-API token with a missing
    checksum field.

    For the stable distribution (lenny), this problem has been fixed in
    version 1.6.dfsg.4~beta1-5lenny4.

    For the testing distribution (squeeze), this problem has been fixed in
    version 1.8.1+dfsg-3.

    For the testing distribution (sid), this problem has been fixed in
    version 1.8.1+dfsg-3.

    We recommend that you upgrade your krb5 packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/k/krb5/krb5_1.6.dfsg.4~beta1-5lenny4.diff.gz
    Size/MD5 checksum: 848699 4e016d8242b7648424be814a39616645
    http://security.debian.org/pool/updates/main/k/krb5/krb5_1.6.dfsg.4~beta1-5lenny4.dsc
    Size/MD5 checksum: 1537 2ffe877c62a1e84a71bf40ca09b00891
    http://security.debian.org/pool/updates/main/k/krb5/krb5_1.6.dfsg.4~beta1.orig.tar.gz
    Size/MD5 checksum: 11647547 08d6ce311204803acbe878ef0bb23c71

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/k/krb5/krb5-doc_1.6.dfsg.4~beta1-5lenny4_all.deb
    Size/MD5 checksum: 2148970 487480f9dd90a66ea45b30a46bd469fb

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/k/krb5/libkrb5-dev_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 93212 39af1e2e97e56cc49e144c1510714fc1
    http://security.debian.org/pool/updates/main/k/krb5/krb5-ftpd_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 72460 230a24dd8ce8cd44189e30a2e3ab673a
    http://security.debian.org/pool/updates/main/k/krb5/krb5-telnetd_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 83604 dc98d768332fecb7450291ac613919ad
    http://security.debian.org/pool/updates/main/k/krb5/krb5-admin-server_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 98844 e79c997e74ed8b37d88083ef44bf4019
    http://security.debian.org/pool/updates/main/k/krb5/libkrb5-dbg_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 1351506 52aba27137ac8375581ebe2a8fe0c9a9
    http://security.debian.org/pool/updates/main/k/krb5/krb5-kdc_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 219044 9278116dedac51494b2476b7713c8953
    http://security.debian.org/pool/updates/main/k/krb5/krb5-clients_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 255506 302e849c061c362ab54cc15e37a5ec1c
    http://security.debian.org/pool/updates/main/k/krb5/krb5-kdc-ldap_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 112606 509d66ed7c568e29ea9f0648d12ff335
    http://security.debian.org/pool/updates/main/k/krb5/krb5-user_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 148342 0ec171235494b9d04cfccce4ff1722da
    http://security.debian.org/pool/updates/main/k/krb5/krb5-pkinit_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 69824 9e74ac0a6dce328f0e0eed2d2f1f3edf
    http://security.debian.org/pool/updates/main/k/krb5/libkrb53_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 538210 7a0d1c002a2ca3dbf57fcd8b39e72c5c
    http://security.debian.org/pool/updates/main/k/krb5/krb5-rsh-server_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 98750 4fe06b7cab12ac33c81b577d16d2e9e1
    http://security.debian.org/pool/updates/main/k/krb5/libkadm55_1.6.dfsg.4~beta1-5lenny4_alpha.deb
    Size/MD5 checksum: 180172 4ddaa9248aca121f6ea580bdff323277

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/k/krb5/libkrb5-dev_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 93582 0b074640128865b73ac0cfa727bd1a43
    http://security.debian.org/pool/updates/main/k/krb5/krb5-ftpd_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 68556 577791b743c31dc3ea86ef40a96d0d65
    http://security.debian.org/pool/updates/main/k/krb5/krb5-admin-server_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 93382 0721c7634225f750b4cfd702b951f852
    http://security.debian.org/pool/updates/main/k/krb5/krb5-rsh-server_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 94502 4ce752f3cb116e862ea10a08baa73db8
    http://security.debian.org/pool/updates/main/k/krb5/krb5-user_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 145160 8ab460824d9017091cacde79fff0e644
    http://security.debian.org/pool/updates/main/k/krb5/krb5-kdc-ldap_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 108572 1738b16ba0f67dc7f0f9c6f006fc3e57
    http://security.debian.org/pool/updates/main/k/krb5/libkadm55_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 169816 1f2f7323645080fb7dd5a337ca90da16
    http://security.debian.org/pool/updates/main/k/krb5/libkrb53_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 519994 98d9b8a92a289a30e269cb9847a123a3
    http://security.debian.org/pool/updates/main/k/krb5/krb5-clients_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 239468 867c83a3b26cd166b975caa5f080c77d
    http://security.debian.org/pool/updates/main/k/krb5/libkrb5-dbg_1.6.dfsg.4~beta1-5lenny4_amd64.deb
    Size/MD5 checksum: 1474888 8a42a73cff994ade51fe75666cb867df
    http://security.debian.org/pool/updates/main/k/krb5/krb5-kdc_1.6.dfsg.4~beta1-5lenny4_amd64.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Sun Jun 7 03:07:26 2026
      from Sydney, Nsw via Telnet
    • Krenn
      Sun Jun 7 01:30:12 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Sat Jun 6 23:27:30 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (0 / 16)
    Uptime: 161:46:18
    Calls: 12,094
    Calls today: 2
    Files: 15,000
    Messages: 6,517,778

© >>> Magnum BBS <<<, 2026