[Oraclevm-errata] OVMSA-2009-0003 Important: Oracle VM 2.1 krb5 security update

Errata Announcements for Oracle VM oraclevm-errata at oss.oracle.com
Thu Apr 16 14:25:16 PDT 2009


Oracle VM Security Advisory OVMSA-2009-0003

The following updated rpms for Oracle VM 2.1 have been uploaded to the 
Unbreakable Linux Network:

i386:
krb5-libs-1.6.1-31.el5_3.3.i386.rpm
krb5-server-1.6.1-31.el5_3.3.i386.rpm
krb5-workstation-1.6.1-31.el5_3.3.i386.rpm


SRPMS:
http://oss.oracle.com/oraclevm/server/SRPMS-updates/krb5-1.6.1-31.el5_3.3.src.rpm


Description of changes:

Following security fixes are released in this errata:

CVE-2009-0844 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0844>
  The get_input_token function in the SPNEGO implementation in MIT 
Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause 
a denial of    service (daemon crash) and possibly obtain sensitive 
information via a crafted length value that triggers a buffer over-read.

CVE-2009-0845 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0845>
 The spnego_gss_accept_sec_context function in 
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 
1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of 
service (NULL pointer dereference and daemon crash) via invalid 
ContextFlags data in the reqFlags field in a negTokenInit token.

CVE-2009-0846 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846>
 The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in 
the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 
1.6.4 allows remote attackers to cause a denial of service (daemon 
crash) or possibly execute arbitrary code via vectors involving an 
invalid DER encoding that triggers a free of an uninitialized pointer.

[1.6.1-31.el5_3.3]
- update to revised patch for CVE-2009-0844/CVE-2009-0845

[1.6.1-31.el5_3.2]
- add fix for potential buffer read overrun in the SPNEGO GSSAPI mechanism
  (#490635, CVE-2009-0844)
- add fix for NULL pointer dereference when handling certain error cases
  in the SPNEGO GSSAPI mechanism (#490635, CVE-2009-0845)
- add fix for attempt to free uninitialized pointer in the ASN.1 decoder
  (#490635, CVE-2009-0846)
- add fix for bug in length validation in the ASN.1 decoder (CVE-2009-0847)

[1.6.1-31.el5_3.1]
- add backport of svn patch to fix a bug in how the gssapi library
  handles certain error cases in gss_accept_sec_context (CVE-2009-0845,

[1.6.1-31.el5_3]
- add a backported patch which adds a check on credentials obtained from
  a foreign realm to make sure that they're of an acceptable type, and
  if not, retry to the request to get one of the right type (Sadique Puthen,

[1.6.1-30.el5_3]
- backport fix from 1.6.3 to register file-based ccaches created with
  the krb5_cc_new_unique() function with the global list, so that we
  don't crash when we go to close the ccache (#468729)

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://oss.oracle.com/pipermail/oraclevm-errata/attachments/20090416/8248f7f4/attachment.html 


More information about the Oraclevm-errata mailing list