让您全面了解并上手亿速云产品
常见入门级使用教程
对外 API 开发文档中心
您历史提交的工单
您的每一条意见,我们都严谨处理
您的每一条建议,我们都认真对待
CNNVD-ID编号 | CNNVD-200706-434 | CVE编号 | CVE-2007-2442 |
发布时间 | 2006-06-01 | 更新时间 | 2021-02-03 |
漏洞类型 | 其他 | 漏洞来源 | N/A |
危险等级 | 超危 | 威胁类型 | 远程 |
厂商 | mit |
Kerberos是美国麻省理工学院(MIT)开发的一套网络认证协议,它采用客户端/服务器结构,并且客户端和服务器端均可对对方进行身份认证(即双重验证),可防止窃听、防止replay攻击等。MIT Kerberos 5(又名krb5)是美国麻省理工学院(MIT)开发的一套网络认证协议,它采用客户端/服务器结构,并且客户端和服务器端均可对对方进行身份认证(即双重验证),可防止窃听、防止replay攻击等。
Kerberos在处理畸形的RPC数据时存在漏洞,远程攻击者可能利用此漏洞导致服务崩溃。
Kerberos src/lib/rpc/svc_auth_gssapi.c文件中的gssrpc__svcauth_gssapi()函数声明了auth_gssapi_creds类型的自动变量creds,这个类型包含有gss_buffer_desc。如果gssrpc__svcauth_gssapi()接收到了长度为0的RPC凭据的话,就会跳转到error标签执行一些清除代码。这时creds中的gss_buffer_desc仍未被初始化,而清除代码试图对creds调用xdr_free(),然后xdr_free()试图释放gss_buffer_desc未初始化的value成员所指向的内存。很难利用释放无效指针执行任意代码,取决于特定malloc实现中的各种因素。成功攻击可能导致完全入侵Kerberos密钥数据库,破坏KDC主机的安全性(kadmind通常以root用户权限运行),不成功的攻击也会导致kadmind崩溃。
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian
------
Debian已经为此发布了一个安全公告(DSA-1323-1)以及相应补丁:
DSA-1323-1:New krb5 packages fix several vulnerabilities
链接:
http://www.debian.org/security/2007/dsa-1323
补丁下载:
Source archives:
http://security.debian.org/pool/updates/main/k/krb5/krb5_1.3.6-2sarge5.dsc
Size/MD5 checksum:782 b600466763baa4f89a8fed5a832eb9d3
http://security.debian.org/pool/updates/main/k/krb5/krb5_1.3.6-2sarge5.diff.gz
Size/MD5 checksum: 669293 0e9dfa39e8db2e0ce871ba40c46c925e
http://security.debian.org/pool/updates/main/k/krb5/krb5_1.3.6.orig.tar.gz
Size/MD5 checksum:6526510 7974d0fc413802712998d5fc5eec2919
Architecture independent components:
http://security.debian.org/pool/updates/main/k/krb5/krb5-doc_1.3.6-2sarge5_all.deb
Size/MD5 checksum: 718836 58c01536ff87db5d3492264349fe844c
Alpha architecture:
http://security.debian.org/pool/updates/main/k/krb5/krb5-admin-server_1.3.6-2sarge5_alpha.deb
Size/MD5 checksum: 115250 ac5498fab92f1047f47f45bb8269fcee
http://security.debian.org/pool/updates/main/k/krb5/krb5-clients_1.3.6-2sarge5_alpha.deb
Size/MD5 checksum: 247680 f5201ab228a84b6f25ed42e422f6fd92
http://security.debian.org/pool/updates/main/k/krb5/krb5-ftpd_1.3.6-2sarge5_alpha.deb
Size/MD5 checksum:62994 fd67dbebb83e11fe7a8d35b4a5209293
http://security.debian.org/pool/updates/main/k/krb5/krb5-kdc_1.3.6-2sarge5_alpha.deb
Size/MD5 checksum: 137138 d44e84b8e1c36215644d8224ae685e96
http://security.debian.org/pool/updates/main/k/krb5/krb5-rsh-server_1.3.6-2sarge5_alpha.deb
Size/MD5 checksum:89720 a4b4f7829ef043e7013887fdb967606f
http://security.debian.org/pool/updates/main/k/krb5/krb5-telnetd_1.3.6-2sarge5_alpha.deb
Size/MD5 checksum:72246 cf93e00c42669deba711fcfbde5285c8
http://security.debian.org/pool/updates/main/k/krb5/krb5-user_1.3.6-2sarge5_alpha.deb
Size/MD5 checksum: 144880 e71073e49208fae27ef0a20c7920ad48
http://security.debian.org/pool/updates/main/k/krb5/libkadm55_1.3.6-2sarge5_alpha.deb
Size/MD5 checksum: 201848 7e5171239d1e3970665029a2286acbb4
http://security.debian.org/pool/updates/main/k/krb5/libkrb5-dev_1.3.6-2sarge5_alpha.deb
Size/MD5 checksum: 861082 4017652625bc8408d5e1eb3f056699c4
http://security.debian.org/pool/updates/main/k/krb5/libkrb53_1.3.6-2sarge5_alpha.deb
Size/MD5 checksum: 422580 385ae85ece57a191de28006b2b1ed342
AMD64 architecture:
http://security.debian.org/pool/updates/main/k/krb5/krb5-admin-server_1.3.6-2sarge5_amd64.deb
Size/MD5 checksum: 104806 d3cb00189b4a3860ed2c89620733d4bb
http://security.debian.org/pool/updates/main/k/krb5/krb5-clients_1.3.6-2sarge5_amd64.deb
Size/MD5 checksum: 216896 c33630904c3b747231ab395734213076
http://security.debian.org/pool/updates/main/k/krb5/krb5-ftpd_1.3.6-2sarge5_amd64.deb
Size/MD5 checksum:56952 7a55c1a696cf6d7afe84fdbc0ecc59c5
http://security.debian.org/pool/updates/main/k/krb5/krb5-kdc_1.3.6-2sarge5_amd64.deb
Size/MD5 checksum: 124744 600f391ee2adc80b057309ccd45b0748
http://security.debian.org/pool/updates/main/k/krb5/krb5-rsh-server_1.3.6-2sarge5_amd64.deb
Size/MD5 checksum:82710 8baedacdf63faf0bf27c41997f15a0d7
http://security.debian.org/pool/updates/main/k/krb5/krb5-telnetd_1.3.6-2sarge5_amd64.deb
Size/MD5 checksum:63508 9b9d4ab137302d171649de86dbd5f2a7
http://security.debian.org/pool/updates/main/k/krb5/krb5-user_1.3.6-2sarge5_amd64.deb
Size/MD5 checksum: 137754 536e88b5bdab0b8385fdd151d7295555
http://security.debian.org/pool/updates/main/k/krb5/libkadm55_1.3.6-2sarge5_amd64.deb
Size/MD5 checksum: 177638 47af31f544051191e34a81bb230f3e69
http://security.debian.org/pool/updates/main/k/krb5/libkrb5-dev_1.3.6-2sarge5_amd64.deb
Size/MD5 checksum: 652300 64c39da5cd28173831c590c1a61024e1
http://security.debian.org/pool/updates/main/k/krb5/libkrb53_1.3.6-2sarge5_amd64.deb
Size/MD5 checksum: 369328 e69e658a600a340b7a981052cc93ba9f
ARM architecture:
http://security.debian.org/pool/updates/main/k/krb5/krb5-admin-server_1.3.6-2sarge5_arm.deb
Size/MD5 checksum:93646 faaef2bab601737cacaf68e76e3dbf34
http://security.debian.org/pool/updates/main/k/krb5/krb5-c
来源:SECUNIA
来源:SECUNIA
来源:SECUNIA
来源:SECUNIA
来源:UBUNTU
来源:SECUNIA
来源:CONFIRM
来源:VUPEN
来源:HP
链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02257427
来源:SECUNIA
来源:APPLE
链接:http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
来源:SECUNIA
来源:CERT
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/35082
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10631
来源:SECUNIA
来源:REDHAT
来源:VUPEN
来源:SECUNIA
来源:CONFIRM
链接:https://secure-support.novell.com/KanisaPlatform/Publishing/773/3248163_f.SAL_Public.html
来源:SUNALERT
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102914-1
来源:TRUSTIX
来源:SECTRACK
来源:REDHAT
来源:GENTOO
来源:BID
来源:SECUNIA
来源:DEBIAN
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/472432/100/0/threaded
来源:SECUNIA
来源:OSVDB
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7344
来源:BID
来源:SECUNIA
来源:SECUNIA
来源:CERT-VN
来源:VUPEN
来源:SECUNIA
来源:CONFIRM
来源:VUPEN
来源:VUPEN
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/472288/100/0/threaded
来源:SUSE
链接:http://www.novell.com/linux/security/advisories/2007_38_krb5.html
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/472507/30/5970/threaded
来源:VUPEN
来源:FULLDISC
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
来源:SECUNIA
来源:CONFIRM
链接:http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2007-004.txt
来源:CONFIRM
链接:http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-004.txt
来源:MANDRIVA
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2007:137