Submitted by KeesCook on Mon, 2007-01-15 12:07
Referenced CVEs:
CVE-2006-6143
Description:
===========================================================
Ubuntu Security Notice USN-408-1 January 15, 2007
krb5 vulnerability
CVE-2006-6143
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libkadm55 1.4.3-5ubuntu0.2
libkrb53 1.4.3-5ubuntu0.2
Ubuntu 6.10:
libkadm55 1.4.3-9ubuntu1.1
libkrb53 1.4.3-9ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
The server-side portion of Kerberos' RPC library had a memory
management flaw which allowed users of that library to call a function
pointer located in unallocated memory. By doing specially crafted
calls to the kadmind server, a remote attacker could exploit this to
execute arbitrary code with root privileges on the target computer.


