Referenced CVEs:
CVE-2008-0062, CVE-2008-0063, CVE-2008-0947
Description:
===========================================================
Ubuntu Security Notice USN-587-1 March 19, 2008
krb5 vulnerabilities
CVE-2008-0062, CVE-2008-0063, CVE-2008-0947
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libkadm55 1.4.3-5ubuntu0.7
libkrb53 1.4.3-5ubuntu0.7
Ubuntu 6.10:
libkadm55 1.4.3-9ubuntu1.6
libkrb53 1.4.3-9ubuntu1.6
Ubuntu 7.04:
libkadm55 1.4.4-5ubuntu3.4
libkrb53 1.4.4-5ubuntu3.4
Ubuntu 7.10:
libkadm55 1.6.dfsg.1-7ubuntu0.1
libkrb53 1.6.dfsg.1-7ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that krb5 did not correctly handle certain krb4
requests. An unauthenticated remote attacker could exploit this flaw
by sending a specially crafted traffic, which could expose sensitive
information, cause a crash, or execute arbitrary code. (CVE-2008-0062,
CVE-2008-0063)
A flaw was discovered in the kadmind service's handling of file
descriptors. An unauthenticated remote attacker could send specially
crafted requests that would cause a crash, resulting in a denial of
service. Only systems with configurations allowing large numbers of
open file descriptors were vulnerable. (CVE-2008-0947)



