CVE-2011-1527 – krb5: KDC denial of service vulnerabilities (MITKRB5-SA-2011-006)
https://notcve.org/view.php?id=CVE-2011-1527
The kdb_ldap plugin in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.1, when the LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a kinit operation with incorrect string case for the realm, related to the is_principal_in_realm, krb5_set_error_message, krb5_ldap_get_principal, and process_as_req functions. El plug-in kdb_ldap en el centro de distribución de claves (KDC) en MIT Kerberos 5 (krb5) v1.9 a v1.9.1, cuando el back end LDAP es utilizado, permite a atacantes remotos provocar una denegación de servicio (puntero a NULL y caída del demonio) a través de una operación de kinit en la cadena incorrecta, en relación con la is_principal_in_realm, krb5_set_error_message, krb5_ldap_get_principal, y las funciones process_as_req. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629558 http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-006.txt http://www.kb.cert.org/vuls/id/659251 http://www.mandriva.com/security/advisories?name=MDVSA-2011:159 http://www.redhat.com/support/errata/RHSA-2011-1379.html https://access.redhat.com/security/cve/CVE-2011-1527 https://bugzilla.redhat.com/show_bug.cgi?id=737711 • CWE-20: Improper Input Validation •
CVE-2011-1528 – krb5: KDC denial of service vulnerabilities (MITKRB5-SA-2011-006)
https://notcve.org/view.php?id=CVE-2011-1528
The krb5_ldap_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the LDAP back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, related to the locked_check_p function. NOTE: the Berkeley DB vector is covered by CVE-2011-4151. La función krb5_ldap_lockout_audit en el Key Distribution Center (KDC) en MIT Kerberos 5 (también se conoce como krb5) versión 1.8 hasta 1.8.4 y versión 1.9 hasta 1.9.1, cuando se utiliza el back-end LDAP, permite a los atacantes remotos causar una denegación de servicio (fallo de aserción y salida de demonio) por medio de vectores no especificados, relacionados con la función locked_check_p. NOTA: El vector Berkeley DB está cubierto por CVE-2011-4151. • http://lists.opensuse.org/opensuse-security-announce/2011-10/msg00009.html http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-006.txt http://www.kb.cert.org/vuls/id/659251 http://www.mandriva.com/security/advisories?name=MDVSA-2011:159 http://www.mandriva.com/security/advisories?name=MDVSA-2011:160 http://www.redhat.com/support/errata/RHSA-2011-1379.html https://bugs.launchpad.net/ubuntu/+source/krb5/+bug/715579 https://access.redhat.com/security/cve/CVE-2011-1528 htt • CWE-20: Improper Input Validation •
CVE-2011-1529 – krb5: KDC denial of service vulnerabilities (MITKRB5-SA-2011-006)
https://notcve.org/view.php?id=CVE-2011-1529
The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the db2 (aka Berkeley DB) or LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger certain process_as_req errors. La function lookup_lockout_policy function del centro de distribución de claves (“Key Distribution Center” o KDC) en MIT Kerberos 5 (krb5) 1.8 hasta la version 1.8.4 y 1.9 hasta la 1.9.1, si db2 (Berkeley DB) o el back end LDAP es utilizado, permite a atacantes remotos provocar una denegación de servicio (resolución de puntero NULL y caída del demonio) a través de vectores que provocan determinados errores process_as_req. • http://lists.opensuse.org/opensuse-security-announce/2011-10/msg00009.html http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-006.txt http://www.kb.cert.org/vuls/id/659251 http://www.mandriva.com/security/advisories?name=MDVSA-2011:159 http://www.mandriva.com/security/advisories?name=MDVSA-2011:160 http://www.redhat.com/support/errata/RHSA-2011-1379.html https://access.redhat.com/security/cve/CVE-2011-1529 https://bugzilla.redhat.com/show_bug.cgi?id=737711 • CWE-20: Improper Input Validation •
CVE-2011-1526 – krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005)
https://notcve.org/view.php?id=CVE-2011-1526
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script. ftpd.c en el demonio GSS-API FTP en MIT Kerberos Version 5 Applications (también conocido como krb5-appl) v1.0.1 y anteriores no comprueban el valor de retorno krb5_setegid, lo que permite que usuarios autenticados de forma remota evitar las restricciones de acceso de grupo, y crear, sobreescribir, borrar, o leer ficheros, a través de comandos FTP estándar, relacionado con test autoconfigurados olvidados en un script configurado. It was found that ftpd, a Kerberos-aware FTP server, did not properly drop privileges. On Red Hat Enterprise Linux 5, the ftpd daemon did not check for the potential failure of the krb5_setegid() function call. On systems where the set real, set effective, or set saved group ID system calls might fail, a remote FTP user could use this flaw to gain unauthorized read or write access to files that were owned by the root group. • http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062681.html http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062699.html http://lists.opensuse.org/opensuse-security-announce/2011-10/msg00009.html http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00002.html http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00004.html http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00005.html http://lists.opensuse.org/opensuse-security-announce/201 • CWE-269: Improper Privilege Management •
CVE-2011-0285 – MIT Kerberos 5 - kadmind Change Password Feature Remote Code Execution
https://notcve.org/view.php?id=CVE-2011-0285
The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition. La función process_chpw_request de schpw.c en la funcionalidad de cambio de contraseña de kadmind de MIT Kerberos 5 (krb5) 1.7 hasta la 1.9 libera un puntero inválido, lo que permite a atacantes remotos ejecutar código de su elección o provocar una denegación de servicio (caída del demonio) a través de una petición modificada que provoca una condición de error. • https://www.exploit-db.com/exploits/35606 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621726 http://krbdev.mit.edu/rt/Ticket/Display.html?id=6899 http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058181.html http://osvdb.org/71789 http://secunia.com/advisories/44125 http://secunia.com/advisories/44181 http://secunia.com/advisories/44196 http://securityreason.com/securityalert/8200 http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-004.txt http:/ • CWE-20: Improper Input Validation •