Summary
The remote host is missing an update to heimdal
announced via advisory DSA 476-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20476-1
Insight
According to a security advisory from the heimdal project:
http://www.pdc.kth.se/heimdal/advisory/2004-04-01/
heimdal, a suite of software implementing the Kerberos protocol, has a cross-realm vulnerability allowing someone with control over a realm to impersonate anyone in the cross-realm trust path.
For the current stable distribution (woody) this problem has been fixed in version 0.4e-7.woody.8.1.
For the unstable distribution (sid), this problem has been fixed in version 0.6.1-1.
We recommend that you update your heimdal package.
Severity
Classification
-
CVE CVE-2004-0371 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
Related Vulnerabilities