The remote host is missing updates announced in advisory CLA-2003:639.
The krb5 packages are MIT's[1] implementation of the Kerberos 5 authentication protocol.
This update fixes the vulnerabilities outlined below:
1. Principal name handling vulnerabilities[2] (CVE-2003-0082[3] and CVE-2003-0072[4])
2. Cryptographic weaknesses in Kerberos v4 protocol[5] (CVE-2003-0138[6] and CVE-2003-0139[7])
3. Faulty length checks in xdrmem_getbytes[8] (CVE-2003-0028[9]) The xdrmem_*() script_family( of functions (such as xdrmem_getbytes()) from the XDR library used by MIT Kerberos contains integer overflows that may be exploited by remote (but authenticated) attackers to cause a denial of service condition or even expose sensitive information.
4. Multiple vulnerabilities in old releases of MIT Kerberos[10]
This announcement upgrades the Kerberos packages in Conectiva Linux 8 to the 1.2.8 version. Please note that Conectiva Linux 9 includes a patched 1.2.7 version and is not vulnerable to these issues.
Solution: The apt tool can be used to perform RPM package upgrades by running 'apt-get update' followed by 'apt-get upgrade'