Secunia Logo
Netsikker nu! 2008
 
Fedora Core 5 update for krb5
Secunia Advisory: SA23707
Release Date: 2007-01-10
Popularity: 5,675 views

Critical:
Highly critical
Impact: Privilege escalation
DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:Fedora Core 5

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-3084
CVE-2006-6143


Description:
Fedora has issued an update for krb5. This fixes two vulnerabilities, which can be exploited by malicious, local users to perform certain actions with escalated privileges, or by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

For more information:
SA21402
SA23696

Solution:
Apply updated packages.

7793a2b82312ff8cd74eed932f19fd140fde8dbc SRPMS/krb5-1.4.3-5.3.src.rpm
7793a2b82312ff8cd74eed932f19fd140fde8dbc noarch/krb5-1.4.3-5.3.src.rpm
80872f714bccacb4a0fe819cf056d08b8b6f2acb ppc/debug/krb5-debuginfo-1.4.3-5.3.ppc.rpm
be455c361d844ed4ec7ff77babef73bf0f1fc135 ppc/krb5-devel-1.4.3-5.3.ppc.rpm
03c13c6e72b3712c81ae4e7a8204c18c8844827a ppc/krb5-libs-1.4.3-5.3.ppc.rpm
f9407fb7e90f1110b0292c16c3396283cf31de00 ppc/krb5-server-1.4.3-5.3.ppc.rpm
c8b605fca4374ed90477c56db750e1071e255857 ppc/krb5-workstation-1.4.3-5.3.ppc.rpm
fad46a7c60b6eb14fb7be738a8f0aecfe5f43e91 x86_64/krb5-devel-1.4.3-5.3.x86_64.rpm
60fe48a00502de2943e3dd0a638905365fb2fcc5 x86_64/krb5-libs-1.4.3-5.3.x86_64.rpm
8e25791a803d4a33dd86bce562d4280b00afaeb3 x86_64/debug/krb5-debuginfo-1.4.3-5.3.x86_64.rpm
5a7ec7ebdeb2e76becec5d525824c44a6a50c3ba x86_64/krb5-workstation-1.4.3-5.3.x86_64.rpm
2fe1049372d5c4b932995fd11f17f954ea778aa6 x86_64/krb5-server-1.4.3-5.3.x86_64.rpm
d284d66778ff2f1f379f82743fcdd8101123c5a6 i386/krb5-server-1.4.3-5.3.i386.rpm
ce685e8dc97cefb790da2a9660d12c42d0ba44c2 i386/krb5-libs-1.4.3-5.3.i386.rpm
bbf873cfbc83e1a1f3ed5e4058b90fef0ba725e3 i386/krb5-devel-1.4.3-5.3.i386.rpm
83f98440fe6ea3012d4534453b3348914c255709 i386/debug/krb5-debuginfo-1.4.3-5.3.i386.rpm
239fd28094e8e8b95f8cadff7adebcc19cde1f11 i386/krb5-workstation-1.4.3-5.3.i386.rpm

Original Advisory:
http://fedoranews.org/cms/node/2376

Other References:
SA21402:
http://secunia.com/advisories/21402/

SA23696:
http://secunia.com/advisories/23696/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

7th Oct, 2008
New advisories: 19
New vulnerabilities: 68
Updated advisories: 62

Moderately // 325 views
Debian update for php5
Moderately // 252 views
Atarone CMS Multiple Vulnerabilities
Moderately // 283 views
Debian update for squid
Less // 283 views
SUSE update for mercurial
Moderately // 330 views
SUSE update for openssh
Less // 264 views
Fedora update for mediawiki

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB "url" bbcode Script Insertion Vulnerability // 94 views
2. phpBB BBcode "url" Script Insertion Vulnerability // 71 views
3. Juniper Products Neighbor Discovery Protocol Neighbor Solicitation Vulnerability // 37 views
4. SUSE update for openssh // 32 views
5. H-Sphere webshell4 Cross-Site Scripting and Request Forgery // 29 views
6. MetaGauge Directory Traversal Vulnerability // 28 views
7. Atarone CMS Multiple Vulnerabilities // 28 views
8. CMME Information Disclosure Security Issues // 28 views
9. Debian update for php5 // 27 views
10. SUSE update for dovecot and graphicsmagic // 27 views