USN-881-1: Kerberos vulnerability

Ubuntu Security Notice USN-881-1

12th January, 2010

krb5 vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 9.10
  • Ubuntu 9.04
  • Ubuntu 8.10
  • Ubuntu 8.04 LTS
  • Ubuntu 6.06 LTS

Software description

  • krb5

Details

It was discovered that Kerberos did not correctly handle invalid AES
blocks. An unauthenticated remote attacker could send specially crafted
traffic that would crash the KDC service, leading to a denial of service,
or possibly execute arbitrary code with root privileges.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 9.10:
libk5crypto3 1.7dfsg~beta3-1ubuntu0.3
Ubuntu 9.04:
libkrb53 1.6.dfsg.4~beta1-5ubuntu2.2
Ubuntu 8.10:
libkrb53 1.6.dfsg.4~beta1-3ubuntu0.3
Ubuntu 8.04 LTS:
libkrb53 1.6.dfsg.3~beta1-2ubuntu1.3
Ubuntu 6.06 LTS:
libkrb53 1.4.3-5ubuntu0.10

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system upgrade is sufficient to effect the
necessary changes.

References

CVE-2009-4212