Aviso de seguridad de Debian

DSA-273-1 krb4 -- debilidad en el cifrado

Fecha del informe:
28 de mar de 2003
Paquetes afectados:
krb4
Vulnerable:
Referencias a bases de datos de seguridad:
En el diccionario CVE de Mitre: CVE-2003-0138, CVE-2003-0139.
Notas y avisos de incidentes y vulnerabilidades en CERT: VU#623217, VU#442569.
Información adicional:

Una debilidad en el cifrado en la versión 4 del protocolo Kerberos permitía a un atacante usar un ataque de texto conocido para hacerse por cualquier principal en un dominio. Una debilidad adicional en el cifrado en la implementación krb4 permitía el uso de ataques de copiar y pegar para fabricar tickets krb4 para clientes principales no autorizados si se usaban claves triple-DES en los servicios de claves de krb4. Estos ataques podían comprometer completamente la infraestructura de autentificación de un sistema que utilizara Kerberos.

Para la distribución estable (woody), este problema se ha corregido en la versión 1.1-8-2.3.

Para la distribución estable anterior (potato), este problema se ha corregido en la versión 1.0-2.3.

Para la distribución inestable (sid), este problema se ha corregido en la versión 1.2.2-1.

Le recomendamos que actualice inmediatamente el paquete krb4.

Arreglado en:

Debian GNU/Linux 2.2 (potato)

Fuentes:
http://security.debian.org/pool/updates/main/k/krb4/krb4_1.0-2.3.dsc
http://security.debian.org/pool/updates/main/k/krb4/krb4_1.0-2.3.diff.gz
http://security.debian.org/pool/updates/main/k/krb4/krb4_1.0.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.0-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.0-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.0-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.0-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.0-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.0-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.0-2.3_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.0-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.0-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.0-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.0-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.0-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.0-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.0-2.3_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.0-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.0-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.0-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.0-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.0-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.0-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.0-2.3_i386.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.0-2.2_m68k.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.0-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.0-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.0-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.0-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.0-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.0-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.0-2.3_sparc.deb

Debian GNU/Linux 3.0 (woody)

Fuentes:
http://security.debian.org/pool/updates/main/k/krb4/krb4_1.1-8-2.3.dsc
http://security.debian.org/pool/updates/main/k/krb4/krb4_1.1-8-2.3.tar.gz
Componentes independientes de la arquitectura:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-docs_1.1-8-2.3_all.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-services_1.1-8-2.3_all.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-user_1.1-8-2.3_all.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-x11_1.1-8-2.3_all.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth1_1.1-8-2.3_all.deb
Alpha:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_alpha.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_arm.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_i386.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_ia64.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_hppa.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_m68k.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_mips.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_mipsel.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_powerpc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_s390.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-clients-x_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-dev-common_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kdc_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-kip_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/kerberos4kth-servers-x_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/libacl1-kerberos4kth_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkadm1-kerberos4kth_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkdb-1-kerberos4kth_1.1-8-2.3_sparc.deb
http://security.debian.org/pool/updates/main/k/krb4/libkrb-1-kerberos4kth_1.1-8-2.3_sparc.deb

Las sumas MD5 de los ficheros que se listan están disponibles en el aviso original.