Multiple vulnerabilities have been identified in MIT Kerberos, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system.
The first issue is caused by a buffer overflow error in the implementation of the RPCSEC_GSS authentication and the "svcauth_gss_validate()" [src/lib/rpc/svc_auth_gss.c] function when processing RPC messages, which could be exploited by remote unauthenticated attackers to crash an affected application or execute arbitrary code with elevated privileges.
The second vulnerability is caused by a memory corruption error in the "kadm5_modify_policy_internal()" [src/lib/kadm5/srv/svr_policy.c] function that does not properly check return values of the "krb5_db_get_policy()" function, which could be exploited by authenticated attackers with "modify policy" privileges to crash an affected application or execute arbitrary code with elevated privileges.
Credits
Vulnerabilities reported by Tenable Network Security, ZDI and Garrett Wollman (MIT CSAIL).
ChangeLog
2007-09-05 : Initial release
2007-09-09 : Updated References
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.