| アップデートID: | RHSA-2008:0181-3 |
|---|---|
| タイプ: | Security Advisory |
| 重大性: | 重大/Critical |
| 発行日: | 2008年3月18日 |
| 最終更新日: | 2008年3月18日 |
| 影響のある製品: |
Red Hat Desktop (v. 3) Red Hat Enterprise Linux AS (v. 2.1) Red Hat Enterprise Linux AS (v. 3) Red Hat Enterprise Linux ES (v. 2.1) Red Hat Enterprise Linux ES (v. 3) Red Hat Enterprise Linux WS (v. 2.1) Red Hat Enterprise Linux WS (v. 3) Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor |
| OVAL: | https://rhn.redhat.com/errata/RHSA-2008-0181.html |
| CVEs (cve.mitre.org): |
CVE-2008-0062 CVE-2008-0063 CVE-2008-0948 |
複数のセキュリティの問題を修正したkrb5のアップデートパッケージがRed Hat Enterprise Linux 2.1と3で利用可能になりました。
このアップデートは、レッドハットセキュリティ対策チームによって、深刻度「重大(Critical)」のセキュリティ問題と評価されています。
Kerberosは、対称鍵暗号(symmetric encryption)とトラステッドサードパーティ(鍵配布センター/KDC)を使用して、クライアントとサーバの相互認証を可能にするネットワーク認証システムです。
MIT Kerberos Authentication ServiceとKey Distribution Centerサーバ(krb5kdc) の間でKerberos v4プロトコルのパケットを処理する過程において1つの問題が発見されました。認証を受けていないリモート・アタッカーがこの問題を悪用し 、改変または不完全なKerberos v4プロトコル・リクエストを使ってkrb5kdcデーモンのクラッシュやそのメモリに含まれる情報の開示、任意のコードを実行できてしまいます。 (CVE-2008-0062, CVE-2008-0063)
これはKerberos v4プロトコルの互換性を有効にしたkrb5kdcでのみ発生する問題ですが、Red Hat Enterprise Linux 4ではこれがデフォルトで有効になっています。Kerberos v4プロトコルのサポートは /var/kerberos/krb5kdc/kdc.conf の[kdcdefaults]セクションに v4_mode=none と追加することで無効にできます。
MIT Kerberos kadmindサーバが利用しているライブラリで、1つの問題が発見されました。認証を受けていないリモート・アタッカーがこの問題を悪用して、kadmindをクラッシュさせることができます。特定のリソース制限を設けて構成された システムのみ、この問題の影響を受けます。Red Hat Enterprise Linux 2.1もしくは3のデフォルトのリソース制限では影響を受けません。 (CVE-2008-0948)
レッドハットは、この問題の報告についてMITに感謝します。
全てのkrb5のユーザは、これらの問題を解決する上記アップデートパッケージにアップグレードしてください。
| Red Hat Desktop (v. 3) | |
| SRPMS: | |
| krb5-1.2.7-68.src.rpm | 42da88bdd9fe9adb7e272ec1e5b6f841 |
| IA-32: | |
| krb5-devel-1.2.7-68.i386.rpm | 5e8f5eb3275d17825cb2fefc58b49dcc |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-server-1.2.7-68.i386.rpm | db6c6bc823b4cb9d6f58b0ae464626a3 |
| krb5-workstation-1.2.7-68.i386.rpm | 7d8f73774b192bca9b11f256f24ae918 |
| x86_64: | |
| krb5-devel-1.2.7-68.x86_64.rpm | cd44012885d41082872e1132ba7a6552 |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-libs-1.2.7-68.x86_64.rpm | ad056b50ef5579107c93bf0b5a98befb |
| krb5-server-1.2.7-68.x86_64.rpm | ff993373a70f300254f87840d6e2e8ba |
| krb5-workstation-1.2.7-68.x86_64.rpm | bd3fab11c8f146b435380c7cf2de2d89 |
| Red Hat Enterprise Linux AS (v. 2.1) | |
| SRPMS: | |
| krb5-1.2.2-48.src.rpm | 3fe933ab13ddd79b9189154250ee80b4 |
| IA-32: | |
| krb5-devel-1.2.2-48.i386.rpm | 8c34c8e99d309abb44836944bcdb59e8 |
| krb5-libs-1.2.2-48.i386.rpm | 055af9ec2284bfd194a096aa3f1e85d4 |
| krb5-server-1.2.2-48.i386.rpm | 3f292540e5f6bcda1104fd5f1fba8fbf |
| krb5-workstation-1.2.2-48.i386.rpm | 44479d795675f9a26734073a445aba84 |
| IA-64: | |
| krb5-devel-1.2.2-48.ia64.rpm | 58f97e4d108c985193e9947a98223a05 |
| krb5-libs-1.2.2-48.ia64.rpm | c6e82f4ce7885819579fc0f50f40520e |
| krb5-server-1.2.2-48.ia64.rpm | eef8b037f731689deaa84eb755df159e |
| krb5-workstation-1.2.2-48.ia64.rpm | 32622b9beb4842a9a32f829f81ccab87 |
| Red Hat Enterprise Linux AS (v. 3) | |
| SRPMS: | |
| krb5-1.2.7-68.src.rpm | 42da88bdd9fe9adb7e272ec1e5b6f841 |
| IA-32: | |
| krb5-devel-1.2.7-68.i386.rpm | 5e8f5eb3275d17825cb2fefc58b49dcc |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-server-1.2.7-68.i386.rpm | db6c6bc823b4cb9d6f58b0ae464626a3 |
| krb5-workstation-1.2.7-68.i386.rpm | 7d8f73774b192bca9b11f256f24ae918 |
| IA-64: | |
| krb5-devel-1.2.7-68.ia64.rpm | 38cd094e4613ff1967976c3ac49597e6 |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-libs-1.2.7-68.ia64.rpm | 5b50fab97ff524bf259d248c25095195 |
| krb5-server-1.2.7-68.ia64.rpm | 78dcc661024ba730d349da748efbb35b |
| krb5-workstation-1.2.7-68.ia64.rpm | 8f8de4cdc7ce4569454eb464b9165a72 |
| PPC: | |
| krb5-devel-1.2.7-68.ppc.rpm | b34a5c4fcada4bc13517fc760f017a95 |
| krb5-libs-1.2.7-68.ppc.rpm | a18d710b6400246c904cc62ba0581cfd |
| krb5-libs-1.2.7-68.ppc64.rpm | dfde2f2bd897ad4a28281c333d7e1b32 |
| krb5-server-1.2.7-68.ppc.rpm | 00fb82b8e2c24767fe9fc61a3ae052be |
| krb5-workstation-1.2.7-68.ppc.rpm | 36b80bb10e5b8479bac0405de0050eec |
| s390: | |
| krb5-devel-1.2.7-68.s390.rpm | f098782a1554ef8f783586c700c756e6 |
| krb5-libs-1.2.7-68.s390.rpm | f9a4123a362d61aa7819f248a76688f1 |
| krb5-server-1.2.7-68.s390.rpm | bf3486b15eaa3caf931d5da92f35cd0e |
| krb5-workstation-1.2.7-68.s390.rpm | cf76c19dc6d259d97b722a940842d929 |
| s390x: | |
| krb5-devel-1.2.7-68.s390x.rpm | 8c35dbc5010f41d9147540c4b8b4d588 |
| krb5-libs-1.2.7-68.s390.rpm | f9a4123a362d61aa7819f248a76688f1 |
| krb5-libs-1.2.7-68.s390x.rpm | 439fbad34301b7a957d34df09de96a1b |
| krb5-server-1.2.7-68.s390x.rpm | cec257e62b71e3d48b2df07d1a6447d1 |
| krb5-workstation-1.2.7-68.s390x.rpm | 612c21cac61bffc4a29ee3260141918d |
| x86_64: | |
| krb5-devel-1.2.7-68.x86_64.rpm | cd44012885d41082872e1132ba7a6552 |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-libs-1.2.7-68.x86_64.rpm | ad056b50ef5579107c93bf0b5a98befb |
| krb5-server-1.2.7-68.x86_64.rpm | ff993373a70f300254f87840d6e2e8ba |
| krb5-workstation-1.2.7-68.x86_64.rpm | bd3fab11c8f146b435380c7cf2de2d89 |
| Red Hat Enterprise Linux ES (v. 2.1) | |
| SRPMS: | |
| krb5-1.2.2-48.src.rpm | 3fe933ab13ddd79b9189154250ee80b4 |
| IA-32: | |
| krb5-devel-1.2.2-48.i386.rpm | 8c34c8e99d309abb44836944bcdb59e8 |
| krb5-libs-1.2.2-48.i386.rpm | 055af9ec2284bfd194a096aa3f1e85d4 |
| krb5-server-1.2.2-48.i386.rpm | 3f292540e5f6bcda1104fd5f1fba8fbf |
| krb5-workstation-1.2.2-48.i386.rpm | 44479d795675f9a26734073a445aba84 |
| Red Hat Enterprise Linux ES (v. 3) | |
| SRPMS: | |
| krb5-1.2.7-68.src.rpm | 42da88bdd9fe9adb7e272ec1e5b6f841 |
| IA-32: | |
| krb5-devel-1.2.7-68.i386.rpm | 5e8f5eb3275d17825cb2fefc58b49dcc |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-server-1.2.7-68.i386.rpm | db6c6bc823b4cb9d6f58b0ae464626a3 |
| krb5-workstation-1.2.7-68.i386.rpm | 7d8f73774b192bca9b11f256f24ae918 |
| IA-64: | |
| krb5-devel-1.2.7-68.ia64.rpm | 38cd094e4613ff1967976c3ac49597e6 |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-libs-1.2.7-68.ia64.rpm | 5b50fab97ff524bf259d248c25095195 |
| krb5-server-1.2.7-68.ia64.rpm | 78dcc661024ba730d349da748efbb35b |
| krb5-workstation-1.2.7-68.ia64.rpm | 8f8de4cdc7ce4569454eb464b9165a72 |
| x86_64: | |
| krb5-devel-1.2.7-68.x86_64.rpm | cd44012885d41082872e1132ba7a6552 |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-libs-1.2.7-68.x86_64.rpm | ad056b50ef5579107c93bf0b5a98befb |
| krb5-server-1.2.7-68.x86_64.rpm | ff993373a70f300254f87840d6e2e8ba |
| krb5-workstation-1.2.7-68.x86_64.rpm | bd3fab11c8f146b435380c7cf2de2d89 |
| Red Hat Enterprise Linux WS (v. 2.1) | |
| SRPMS: | |
| krb5-1.2.2-48.src.rpm | 3fe933ab13ddd79b9189154250ee80b4 |
| IA-32: | |
| krb5-devel-1.2.2-48.i386.rpm | 8c34c8e99d309abb44836944bcdb59e8 |
| krb5-libs-1.2.2-48.i386.rpm | 055af9ec2284bfd194a096aa3f1e85d4 |
| krb5-server-1.2.2-48.i386.rpm | 3f292540e5f6bcda1104fd5f1fba8fbf |
| krb5-workstation-1.2.2-48.i386.rpm | 44479d795675f9a26734073a445aba84 |
| Red Hat Enterprise Linux WS (v. 3) | |
| SRPMS: | |
| krb5-1.2.7-68.src.rpm | 42da88bdd9fe9adb7e272ec1e5b6f841 |
| IA-32: | |
| krb5-devel-1.2.7-68.i386.rpm | 5e8f5eb3275d17825cb2fefc58b49dcc |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-server-1.2.7-68.i386.rpm | db6c6bc823b4cb9d6f58b0ae464626a3 |
| krb5-workstation-1.2.7-68.i386.rpm | 7d8f73774b192bca9b11f256f24ae918 |
| IA-64: | |
| krb5-devel-1.2.7-68.ia64.rpm | 38cd094e4613ff1967976c3ac49597e6 |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-libs-1.2.7-68.ia64.rpm | 5b50fab97ff524bf259d248c25095195 |
| krb5-server-1.2.7-68.ia64.rpm | 78dcc661024ba730d349da748efbb35b |
| krb5-workstation-1.2.7-68.ia64.rpm | 8f8de4cdc7ce4569454eb464b9165a72 |
| x86_64: | |
| krb5-devel-1.2.7-68.x86_64.rpm | cd44012885d41082872e1132ba7a6552 |
| krb5-libs-1.2.7-68.i386.rpm | 87ed05fa065b652d58bdbb1eda72a427 |
| krb5-libs-1.2.7-68.x86_64.rpm | ad056b50ef5579107c93bf0b5a98befb |
| krb5-server-1.2.7-68.x86_64.rpm | ff993373a70f300254f87840d6e2e8ba |
| krb5-workstation-1.2.7-68.x86_64.rpm | bd3fab11c8f146b435380c7cf2de2d89 |
| Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor | |
| SRPMS: | |
| krb5-1.2.2-48.src.rpm | 3fe933ab13ddd79b9189154250ee80b4 |
| IA-64: | |
| krb5-devel-1.2.2-48.ia64.rpm | 58f97e4d108c985193e9947a98223a05 |
| krb5-libs-1.2.2-48.ia64.rpm | c6e82f4ce7885819579fc0f50f40520e |
| krb5-server-1.2.2-48.ia64.rpm | eef8b037f731689deaa84eb755df159e |
| krb5-workstation-1.2.2-48.ia64.rpm | 32622b9beb4842a9a32f829f81ccab87 |
| (The unlinked packages above are only available from the Red Hat Network) | |
432620 - CVE-2008-0062 krb5: uninitialized pointer use in krb5kdc
432621 - CVE-2008-0063 krb5: possible leak of sensitive data from krb5kdc using krb4 request
435087 - CVE-2008-0948 krb5: incorrect handling of high-numbered file descriptors in RPC library
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/