Debian-Sicherheitsankündigung

DSA-184-1 krb4 -- Pufferüberlauf

Datum des Berichts:
30. Okt 2002
Betroffene Pakete:
krb4
Verwundbar:
Ja
Sicherheitsdatenbanken-Referenzen:
In Mitres CVE-Verzeichnis: CVE-2002-1235.
CERTs Verwundbarkeiten, Hinweise und Ereignis-Notizen: CA-2002-29, VU#875073.
Weitere Informationen:

Tom Yu und Sam Hartman vom MIT entdeckten einen weiteren Stapel-Pufferüberlauf in der kadm_ser_wrap_in Funktion des Kerberos v4 Administrations-Servers. Zu diesem kadmind-Fehler ist ein funktionstüchtiger Ausbeutungs-Code im Umlauf, daher wird dies als ernst eingestuft.

Dieses Problem wurde in Version 1.1-8-2.2 für die aktuelle stable Distribution (Woody), in Version 1.0-2.2 für die alte stable Distribution (Potato) und in Version 1.1-11-8 für die unstable Distribution (Sid) behoben.

Wir empfehlen Ihnen, Ihre krb4-Pakete unverzüglich zu aktualisieren.

Behoben in:

Debian GNU/Linux 2.2 (potato)

Quellcode:
http://security.debian.org/pool/updates/main/k/krb4/krb4_1.0-2.2.dsc
http://security.debian.org/pool/updates/main/k/krb4/krb4_1.0-2.2.diff.gz
http://security.debian.org/pool/updates/main/k/krb4/krb4_1.0.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.0-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.0-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.0-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.0-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.0-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.0-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.0-2.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.0-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.0-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.0-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.0-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.0-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.0-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.0-2.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.0-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.0-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.0-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.0-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.0-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.0-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.0-2.2_i386.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.0-2.2_m68k.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.0-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.0-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.0-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.0-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.0-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.0-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.0-2.2_sparc.deb

Debian GNU/Linux 3.0 (woody)

Quellcode:
http://security.debian.org/pool/updates/main/k/krb4/krb4_1.1-8-2.2.dsc
http://security.debian.org/pool/updates/main/k/krb4/krb4_1.1-8-2.2.tar.gz
Architektur-unabhängige Dateien:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-docs_1.1-8-2.2_all.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.1-8-2.2_all.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.1-8-2.2_all.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.1-8-2.2_all.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.1-8-2.2_all.deb
Alpha:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_ia64.deb
HP Precision:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.2_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.2_sparc.deb

MD5-Prüfsummen der aufgeführten Dateien stehen in der ursprünglichen Sicherheitsankündigung zur Verfügung.