krb5-1.6.1-70.AXS3
エラータID: AXSA:2012-256:02
Kerberos V5 is a trusted-third-party network authentication system, which can improve your network's security by eliminating the insecure practice of cleartext passwords.
Security issues fixed with this release:
CVE-2011-1526
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.
Fixed bugs:
• A mistake in the Kerberos libraries could make a client fail to contact a Key Distribution Center or crash if the client already had more than 1024 file descriptors in use. This has been fixed: the Kerberos librairies now use the poll() function instead of the select() function which created those problems.
• If a client request included an authenticator with a subkey, the KDC failed to release memory when processing a ticket-granting server request and consumed an excessive amount of memory. This has been fixed.
• Sometimes, services requiring Kerberos authentication sent two authentication requests to the server. The second one could be flagged as a replay attack and then denied. This has been fixed.
• When Kerberos credentials had expired, the klist command could sometimes crash with a segmentation fault if invoked with the -s option. This has been fixed.
• Multi-line FTP macros could terminate prematurely with a segmentation fault because of a regression. This has been fixed.
Update packages.
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.
N/A
SRPMS
- krb5-1.6.1-70.AXS3.src.rpm
MD5: 24a32a2e8c32110bf69f00c700149fa2
SHA-256: 39a929dcc2d789b46977a19be37c615d3109c714280f7110498333148a211b87
Size: 14.99 MB
Asianux Server 3 for x86
- krb5-devel-1.6.1-70.AXS3.i386.rpm
MD5: a754b3fb74374e16d67c980611eb1f5a
SHA-256: 78f3b3fd8842c3ff9030944daab5d9247deba56fea36ef231cb6f9bc04ed4a60
Size: 1.86 MB - krb5-libs-1.6.1-70.AXS3.i386.rpm
MD5: 7f063e60dec06a0974ab06e6a11a0aa3
SHA-256: c100006a80d6940c865565d7c25ef1eb6274ea3d1ff576219617701f9dd823dc
Size: 670.04 kB - krb5-server-1.6.1-70.AXS3.i386.rpm
MD5: c58e06327c9b180ef9662e54e94a2626
SHA-256: ed0966c726b3803ea30ff43537a7dc851b7c092ce4cd40e8d437672aad33a63d
Size: 913.93 kB - krb5-workstation-1.6.1-70.AXS3.i386.rpm
MD5: de5deaa204702f373c1767be4366a47f
SHA-256: aeff9c79ba2952a428e122e598c995a25622e8281b970ba28e7ec0795e23e8c3
Size: 830.91 kB
Asianux Server 3 for x86_64
- krb5-devel-1.6.1-70.AXS3.x86_64.rpm
MD5: 2ba642f61bb3bf7f0a242c9aaa150f70
SHA-256: 504d59bb0bcbc6e9c4fe1230ce2aaa2a86c113dc533f07a0ca5682989880d5b3
Size: 1.88 MB - krb5-libs-1.6.1-70.AXS3.x86_64.rpm
MD5: 692e34431d54117dd33ba3efb6c5e6dc
SHA-256: 49e45b012cd07e84fe14ffada1f024a07b7e82c513156bbc609a81571140e05f
Size: 682.09 kB - krb5-server-1.6.1-70.AXS3.x86_64.rpm
MD5: f2dd70e8ade88eb4f7e2f005ab8c3c4d
SHA-256: 67a544aab5e01512e27cb44ead4177bfe19f6202d10e8b73028539db520f8a77
Size: 921.74 kB - krb5-workstation-1.6.1-70.AXS3.x86_64.rpm
MD5: e730673dd168bba065c029e80415b054
SHA-256: f6eed576594ff55addcf16320cd61c50785d1b3706a7bc7dde0c3639fc8c1b19
Size: 856.72 kB