Get Certified! Ubuntu Online Training

News

USN-408-1: krb5 vulnerability

=========================================================== Ubuntu Security Notice USN-408-1 January 15, 2007 krb5 vulnerability CVE-2006-6143 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libkadm55 1.4.3-5ubuntu0.2 libkrb53 1.4.3-5ubuntu0.2 Ubuntu 6.10: libkadm55 1.4.3-9ubuntu1.1 libkrb53 1.4.3-9ubuntu1.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: The server-side portion of Kerberos' RPC library had a memory management flaw which allowed users of that library to call a function pointer located in unallocated memory. By doing specially crafted calls to the kadmind server, a remote attacker could exploit this to execute arbitrary code with root privileges on the target computer.