(Sun Issues Fix for Solaris) Kerberos kadmind Stack Overflow and Uninitialized Pointer Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1018657 |
|
SecurityTracker URL: http://securitytracker.com/id/1018657
|
|
CVE Reference:
CVE-2007-3999
(Links to External Site)
|
Date: Sep 6 2007
|
Impact:
Execution of arbitrary code via network, Root access via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): krb5-1.4 through krb5-1.6.2
|
Description:
Two vulnerabilities were reported in Kerberos. A remote user can execute arbitrary code on the target system.
A remote user can send specially crafted data to trigger a stack overflow in the krb5 Kerberos administration daemon (kadmind) in RPCSEC_GSS authentication RPC library [CVE-2007-3999]. Arbitrary code can be executed on the target system, typically with root privileges.
Third-party applications that use the RPC library may be affected.
Tenable Network Security reported this vulnerability via TippingPoint.
A remote authenticated user with 'modify policy' privileges can exploit an uninitialized pointer in kadmind to write arbitrary data to memory [CVE-2007-4000]. Arbitrary code can be executed on the target system, typically with root privileges.
Garrett Wollman of MIT CSAIL reported this vulnerability.
|
Impact:
A remote user can execute arbitrary code on the target system with root privileges.
|
Solution:
Sun has issued the following IDRs as a workaround to CVE-2007-3999, available at:
http://www.sunsolve.sun.com/tpatches
SPARC Platform:
* Solaris 8: IDR127688-02
* Solaris 9: IDR127648-03
* Solaris 10: IDR127545-04
x86 Platform
* Solaris 8: IDR127689-02
* Solaris 9: IDR127649-03
* Solaris 10: IDR127647-03
Solaris is not affected by CVE-2007-4000
The Sun advisory is available at:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103060-1
|
Vendor URL: web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
UNIX (Solaris - SunOS)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Thu, 6 Sep 2007 08:13:55 -0400
Subject: Security Vulnerability in RPCSEC_GSS (rpcsec_gss(3NSL)) Affects Kerberos Administration Daemon (kadmind(1M))
|
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103060-1
CVE-2007-3999
|
|