It was discovered that the krb5 telnet daemon performs insufficient
validation of usernames, which might allow unauthorized logins or
privilege escalation.
CVE-2007-0957
iDefense discovered that a buffer overflow in the logging code of the
KDC and the administration daemon might lead to arbitrary code
execution.
CVE-2007-1216
It was discovered that a double free in the RPCSEC_GSS part of the
GSS library code might lead to arbitrary code execution.
For the stable distribution (sarge) these problems have been fixed in
version 1.3.6-2sarge4.
For the upcoming stable distribution (etch) these problems have been fixed
in version 1.4.4-7etch1.
For the unstable distribution (sid) these problems will be fixed soon.
We recommend that you upgrade your Kerberos packages.
Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get packag...
Get the latest Linux and open source security news straight to your inbox.