Executive Summary
Summary | |
---|---|
Title | New heimdal packages fix authentication failure |
Informations | |||
---|---|---|---|
Name | DSA-269 | First vendor Publication | 2003-03-26 |
Vendor | Debian | Last vendor Modification | 2003-04-09 |
Severity (Vendor) | N/A | Revision | 2 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Due to overzealous applied patches, the security update DSA 269-1 introduced problems in some installations, causing the hprop service to fail. This is corrected with the update below. For completeness, here is the original advisory text: A cryptographic weakness in version 4 of the Kerberos protocol allows an attacker to use a chosen-plaintext attack to impersonate any principal in a realm. Additional cryptographic weaknesses in the krb4 implementation permit the use of cut-and-paste attacks to fabricate krb4 tickets for unauthorized client principals if triple-DES keys are used to key krb4 services. These attacks can subvert a site's entire Kerberos authentication infrastructure. This version of the heimdal package changes the default behavior and disallows cross-realm authentication for Kerberos version 4. Because of the fundamental nature of the problem, cross-realm authentication in Kerberos version 4 cannot be made secure and sites should avoid its use. A new option (--kerberos4-cross-realm) is provided to the kdc command to re-enable version 4 cross-realm authentication for those sites that must use this functionality but desire the other security fixes. For the stable distribution (woody) these problems have been fixed in version 0.4e-7.woody.8. The old stable distribution (potato) is not affected by this problem, since it isn't compiled against kerberos 4. For the unstable distribution (sid) the original problem has been fixed in version 0.5.2-1 and since it was a new upstream version did not contain the problem mentioned above. We recommend that you upgrade your heimdal packages. |
Original Source
Url : http://www.debian.org/security/2003/dsa-269 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:248 | |||
Oval ID: | oval:org.mitre.oval:def:248 | ||
Title: | Kerberos krb4 Plaintext Attack Vulnerability | ||
Description: | Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2003-0138 | Version: | 2 |
Platform(s): | Red Hat Linux 9 | Product(s): | krb5 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 266-1 (krb5) File : nvt/deb_266_1.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 269-1 (heimdal) File : nvt/deb_269_1.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 269-2 (heimdal) File : nvt/deb_269_2.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 273-1 (krb4) File : nvt/deb_273_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
4869 | MIT Kerberos 4 Chosen-plaintext Attack Realm Principle Impersonation |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-266.nasl - Type : ACT_GATHER_INFO |
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-269.nasl - Type : ACT_GATHER_INFO |
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-273.nasl - Type : ACT_GATHER_INFO |
2004-07-31 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2003-043.nasl - Type : ACT_GATHER_INFO |
2004-07-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2003-052.nasl - Type : ACT_GATHER_INFO |
2003-04-03 | Name : The remote host is using an authentication protocol with cryptographic weakne... File : kerberos4_crypto_weaknesses.nasl - Type : ACT_GATHER_INFO |
2003-04-03 | Name : It may be possible to execute arbitrary code on the remote Kerberos server. File : kerberos5_issues.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:31:54 |
|