Kerberos Telnet Encryption Feature Buffer Overflow Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1026463 |
|
SecurityTracker URL: http://securitytracker.com/id/1026463
|
|
CVE Reference:
CVE-2011-4862
(Links to External Site)
|
Date: Dec 27 2011
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in Kerberos. A remote user can execute arbitrary code on the target system.
A remote user can supply a specially crafted encryption key to trigger a buffer overflow and execute arbitrary code on the target system. The code will run with the privileges of the telnet daemon (typically root privileges).
Versions prior to krb5-1.8 and all versions of krb5-appl are affected.
This vulnerability is being actively exploited.
[Editor's note: This vulnerability was previously reported in Alert ID 1026460 as also affecting FreeBSD telnetd.]
|
Impact:
A remote user can execute arbitrary code on the target system.
|
Solution:
The vendor has issued a patch, available at:
http://web.mit.edu/kerberos/advisories/2011-008-patch.txt
The vendor's advisory is available at:
http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-008.txt
|
Vendor URL: web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-008.txt (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 27 Dec 2011 17:54:16 +0000
Subject: MIT krb5
|
http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-008.txt
CVE-2011-4862
|
|