Summary
The remote host is missing an update to krb5
announced via advisory DSA 2379-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202379-1
Insight
It was discovered that the Key Distribution Center (KDC) in Kerberos 5 crashes when processing certain crafted requests:
CVE-2011-1528
When the LDAP backend is used, remote users can trigger a KDC daemon crash and denial of service.
CVE-2011-1529
When the LDAP or Berkeley DB backend is used, remote users can trigger a NULL pointer dereference in the KDC daemon and a denial of service.
The oldstable distribution (lenny) is not affected by these problems.
For the stable distribution (squeeze), these problems have been fixed in version 1.8.3+dfsg-4squeeze5.
For the testing distribution (wheezy) and the unstable distribution (sid), these problems have been fixed in version 1.10+dfsg~alpha1-1.
We recommend that you upgrade your krb5 packages.
Severity
Classification
-
CVE CVE-2011-1528, CVE-2011-1529 -
CVSS Base Score: 7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities