Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2011-0447

Опубликовано: 14 апр. 2011
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2011-0447: krb5 security update (MODERATE)

[1.8.2-3.7]

  • kadmind: add upstream patch to fix free() on an invalid pointer (#696341, MITKRB5-SA-2011-004, CVE-2011-0285)

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

krb5-devel

1.8.2-3.el6_0.7

krb5-libs

1.8.2-3.el6_0.7

krb5-pkinit-openssl

1.8.2-3.el6_0.7

krb5-server

1.8.2-3.el6_0.7

krb5-server-ldap

1.8.2-3.el6_0.7

krb5-workstation

1.8.2-3.el6_0.7

Oracle Linux i686

krb5-devel

1.8.2-3.el6_0.7

krb5-libs

1.8.2-3.el6_0.7

krb5-pkinit-openssl

1.8.2-3.el6_0.7

krb5-server

1.8.2-3.el6_0.7

krb5-server-ldap

1.8.2-3.el6_0.7

krb5-workstation

1.8.2-3.el6_0.7

Связанные CVE

Связанные уязвимости

ubuntu
около 14 лет назад

The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.

redhat
около 14 лет назад

The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.

nvd
около 14 лет назад

The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.

debian
около 14 лет назад

The process_chpw_request function in schpw.c in the password-changing ...

github
около 3 лет назад

The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.