![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.67132 |
Category: | Ubuntu Local Security Checks |
Title: | Ubuntu USN-916-1 (krb5) |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing an update to krb5 announced via advisory USN-916-1. Details follow: Emmanuel Bouillon discovered that Kerberos did not correctly handle certain message types. An unauthenticated remote attacker could send specially crafted traffic to cause the KDC to crash, leading to a denial of service. (CVE-2010-0283) Nalin Dahyabhai, Jan iankko Lieskovsky, and Zbysek Mraz discovered that Kerberos did not correctly handle certain GSS packets. An unauthenticated remote attacker could send specially crafted traffic that would cause services using GSS-API to crash, leading to a denial of service. (CVE-2010-0628) Solution: The problem can be corrected by upgrading your system to the following package versions: Ubuntu 9.10: krb5-kdc 1.7dfsg~ beta3-1ubuntu0.5 libgssapi-krb5-2 1.7dfsg~ beta3-1ubuntu0.5 In general, a standard system upgrade is sufficient to effect the necessary changes. http://www.securityspace.com/smysecure/catid.html?in=USN-916-1 Risk factor : High CVSS Score: 7.8 |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-0283 http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html BugTraq ID: 38260 http://www.securityfocus.com/bid/38260 Bugtraq: 20100216 MITKRB5-SA-2010-001 [CVE-2010-0283] krb5-1.7 KDC denial of service (Google Search) http://www.securityfocus.com/archive/1/509553/100/0/threaded http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035222.html http://securitytracker.com/id?1023593 http://secunia.com/advisories/38598 http://secunia.com/advisories/39023 http://secunia.com/advisories/40220 http://www.ubuntu.com/usn/USN-916-1 http://www.vupen.com/english/advisories/2010/1481 Common Vulnerability Exposure (CVE) ID: CVE-2010-0628 BugTraq ID: 38904 http://www.securityfocus.com/bid/38904 Bugtraq: 20100323 MITKRB5-SA-2010-002 denial of service in SPNEGO [CVE-2010-0628 VU#839413] (Google Search) http://www.securityfocus.com/archive/1/510281/100/0/threaded CERT/CC vulnerability note: VU#839413 http://www.kb.cert.org/vuls/id/839413 |
Copyright | Copyright (c) 2010 E-Soft Inc. http://www.securityspace.com |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |