Submitted by KeesCook on Fri, 2007-09-07 18:01
Referenced CVEs:
CVE-2007-4743
Description:
===========================================================
Ubuntu Security Notice USN-511-2 September 07, 2007
krb5, librpcsecgss vulnerability
CVE-2007-4743
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libkadm55 1.4.3-5ubuntu0.6
librpcsecgss1 0.7-0ubuntu1.2
Ubuntu 6.10:
libkadm55 1.4.3-9ubuntu1.5
librpcsecgss2 0.13-2ubuntu0.2
Ubuntu 7.04:
libkadm55 1.4.4-5ubuntu3.3
librpcsecgss3 0.14-2ubuntu1.2
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
USN-511-1 fixed vulnerabilities in krb5 and librpcsecgss. The fixes were
incomplete, and only reduced the scope of the vulnerability, without fully
solving it. This update fixes the problem.
Original advisory details:
It was discovered that the libraries handling RPCSEC_GSS did not correctly
validate the size of certain packet structures. An unauthenticated remote
user could send a specially crafted request and execute arbitrary code
with root privileges.


