Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.841097
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-1520-1)
Summary:The remote host is missing an update for the 'krb5' package(s) announced via the USN-1520-1 advisory.
Description:Summary:
The remote host is missing an update for the 'krb5' package(s) announced via the USN-1520-1 advisory.

Vulnerability Insight:
Emmanuel Bouillon discovered that the MIT krb5 Key Distribution Center
(KDC) daemon could free an uninitialized pointer when handling a
malformed AS-REQ message. A remote unauthenticated attacker could
use this to cause a denial of service or possibly execute arbitrary
code. (CVE-2012-1015)

Emmanuel Bouillon discovered that the MIT krb5 Key Distribution Center
(KDC) daemon could dereference an uninitialized pointer while handling
a malformed AS-REQ message. A remote unauthenticated attacker could
use this to cause a denial of service or possibly execute arbitrary
code. This issue only affected Ubuntu 12.04 LTS. (CVE-2012-1014)

Simo Source discovered that the MIT krb5 Key Distribution Center (KDC)
daemon could dereference a NULL pointer when handling a malformed
TGS-REQ message. A remote authenticated attacker could use this to
cause a denial of service. (CVE-2012-1013)

It was discovered that the kadmin protocol implementation in MIT krb5
did not properly restrict access to the SET_STRING and GET_STRINGS
operations. A remote authenticated attacker could use this to expose
or modify sensitive information. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-1012)

Affected Software/OS:
'krb5' package(s) on Ubuntu 10.04, Ubuntu 11.04, Ubuntu 11.10, Ubuntu 12.04.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-1012
Common Vulnerability Exposure (CVE) ID: CVE-2012-1013
BugTraq ID: 53784
http://www.securityfocus.com/bid/53784
http://www.mandriva.com/security/advisories?name=MDVSA-2012:102
http://mailman.mit.edu/pipermail/kerberos-announce/2012q2/000136.html
RedHat Security Advisories: RHSA-2012:1131
http://rhn.redhat.com/errata/RHSA-2012-1131.html
SuSE Security Announcement: openSUSE-SU-2012:0834 (Google Search)
https://hermes.opensuse.org/messages/15083635
Common Vulnerability Exposure (CVE) ID: CVE-2012-1014
Debian Security Information: DSA-2518 (Google Search)
http://www.debian.org/security/2012/dsa-2518
SuSE Security Announcement: openSUSE-SU-2012:0967 (Google Search)
http://lists.opensuse.org/opensuse-updates/2012-08/msg00016.html
Common Vulnerability Exposure (CVE) ID: CVE-2012-1015
http://www.mandriva.com/security/advisories?name=MDVSA-2012:120
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.