| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.57651 |
| Category: | Mandrake Local Security Checks |
| Title: | Mandrake Security Advisory MDKSA-2006:218 (apache-mod_auth_kerb) |
| Summary: | Mandrake Security Advisory MDKSA-2006:218 (apache-mod_auth_kerb) |
| Description: | The remote host is missing an update to apache-mod_auth_kerb announced via advisory MDKSA-2006:218. An off-by-one error in the der_get_oid function in mod_auth_kerb 5.0 allows remote attackers to cause a denial of service (crash) via a crafted Kerberos message that triggers a heap-based buffer overflow in the component array. Packages have been patched to correct this issue. Affected: Corporate 4.0 Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2006:218 Risk factor : Medium |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2006-5989 Debian Security Information: DSA-1247 (Google Search) http://www.debian.org/security/2007/dsa-1247 http://security.gentoo.org/glsa/glsa-200701-14.xml http://www.mandriva.com/security/advisories?name=MDKSA-2006:218 http://www.redhat.com/support/errata/RHSA-2006-0746.html BugTraq ID: 21214 http://www.securityfocus.com/bid/21214 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10051 http://www.vupen.com/english/advisories/2006/4633 http://securitytracker.com/id?1017348 http://secunia.com/advisories/23023 http://secunia.com/advisories/23251 http://secunia.com/advisories/23681 http://secunia.com/advisories/23820 XForce ISS Database: apache-modauthkerb-offbyone-bo(30456) http://xforce.iss.net/xforce/xfdb/30456 |
| Copyright | Copyright (c) 2006 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|