Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: heimdal (200305-09)
Date: Tue, 27 May 2003 11:15:16
Message-Id: 20030527084655.EF60133742@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200305-09
6 - - - ---------------------------------------------------------------------
7
8 PACKAGE : heimdal
9 SUMMARY : protocol bug in the kerberos v4 cross-realm operation
10 DATE : 2003-05-27 08:46 UTC
11 EXPLOIT : remote
12 VERSIONS AFFECTED : <heimdal-0.6
13 FIXED VERSION : >=heimdal-0.6
14 CVE : CAN-2003-0139 CAN-2003-0138
15
16 - - - ---------------------------------------------------------------------
17
18 heimdal suffers from the same vulnerability as mit-krb5 does, hence
19 the identical advisory.
20
21 - - From advisory:
22 "A cryptographic weakness in version 4 of the Kerberos protocol allows
23 an attacker to use a chosen-plaintext attack to impersonate any
24 principal in a realm. Additional cryptographic weaknesses in the krb4
25 implementation included in the MIT krb5 distribution permit the use of
26 cut-and-paste attacks to fabricate krb4 tickets for unauthorized
27 client principals if triple-DES keys are used to key krb4 services.
28 These attacks can subvert a site's entire Kerberos authentication
29 infrastructure."
30
31 Read the full advisory at
32 http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt
33
34 SOLUTION
35
36 It is recommended that all Gentoo Linux users who are running
37 app-crypt/heimdal upgrade to heimdal-0.6 as follows
38
39 emerge sync
40 emerge heimdal
41 emerge clean
42
43 - - - ---------------------------------------------------------------------
44 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
45 - - - ---------------------------------------------------------------------
46 -----BEGIN PGP SIGNATURE-----
47 Version: GnuPG v1.2.2 (GNU/Linux)
48
49 iD8DBQE+0yX+fT7nyhUpoZMRAqomAJwOF+s21nzkJEg1TXKMIU6YLQa1wwCgmd5U
50 X2oFKeabiL/2Q3TVIeYQIbM=
51 =PnXC
52 -----END PGP SIGNATURE-----