Ubuntu Security Notice USN-881-1
12th January, 2010
krb5 vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 9.10
- Ubuntu 9.04
- Ubuntu 8.10
- Ubuntu 8.04 LTS
- Ubuntu 6.06 LTS
Software description
- krb5
Details
It was discovered that Kerberos did not correctly handle invalid AES
blocks. An unauthenticated remote attacker could send specially crafted
traffic that would crash the KDC service, leading to a denial of service,
or possibly execute arbitrary code with root privileges.
Update instructions
The problem can be corrected by updating your system to the following package version:
- Ubuntu 9.10:
- libk5crypto3 1.7dfsg~beta3-1ubuntu0.3
- Ubuntu 9.04:
- libkrb53 1.6.dfsg.4~beta1-5ubuntu2.2
- Ubuntu 8.10:
- libkrb53 1.6.dfsg.4~beta1-3ubuntu0.3
- Ubuntu 8.04 LTS:
- libkrb53 1.6.dfsg.3~beta1-2ubuntu1.3
- Ubuntu 6.06 LTS:
- libkrb53 1.4.3-5ubuntu0.10
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system upgrade is sufficient to effect the
necessary changes.