Mandriva Update for krb5 MDKSA-2007:077-1 (krb5)

Solution
Please Install the Updated Packages.
Insight
A vulnerability was found in the username handling of the MIT krb5 telnet daemon. A remote attacker that could access the telnet port of a target machine could login as root without requiring a password (CVE-2007-0956). Buffer overflows in the kadmin server daemon were discovered that could be exploited by a remote attacker able to access the KDC. Successful exploitation could allow for the execution of arbitrary code with the privileges of the KDC or kadmin server processes (CVE-2007-0957). Finally, a double-free flaw was discovered in the GSSAPI library used by the kadmin server daemon, which could lead to a denial of service condition or the execution of arbitrary code with the privileges of the KDC or kadmin server processes (CVE-2007-1216). Updated packages have been patched to address this issue. Update: Packages for Mandriva Linux 2007.1 are now available.
Affected
krb5 on Mandriva Linux 2007.1, Mandriva Linux 2007.1/X86_64