Submitted by KeesCook on Tue, 2007-09-04 23:40
Referenced CVEs:
CVE-2007-3999
Description:
===========================================================
Ubuntu Security Notice USN-511-1 September 04, 2007
krb5, librpcsecgss vulnerability
CVE-2007-3999
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libkadm55 1.4.3-5ubuntu0.5
librpcsecgss1 0.7-0ubuntu1.1
Ubuntu 6.10:
libkadm55 1.4.3-9ubuntu1.4
librpcsecgss2 0.13-2ubuntu0.1
Ubuntu 7.04:
libkadm55 1.4.4-5ubuntu3.2
librpcsecgss3 0.14-2ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that the libraries handling RPCSEC_GSS did not correctly
validate the size of certain packet structures. An unauthenticated remote
user could send a specially crafted request and execute arbitrary code
with root privileges.


