Debian DSA-184-1 : krb4 - buffer overflow

This script is Copyright (C) 2004-2013 Tenable Network Security, Inc.


Synopsis :

The remote Debian host is missing a security-related update.

Description :

Tom Yu and Sam Hartman of MIT discovered another stack buffer overflow
in the kadm_ser_wrap_in function in the Kerberos v4 administration
server. This kadmind bug has a working exploit code circulating, hence
it is considered serious.

See also :

http://www.debian.org/security/2002/dsa-184

Solution :

Upgrade the krb4 packages immediately.

This problem has been fixed in version 1.1-8-2.2 for the current
stable distribution (woody), in version 1.0-2.2 for the old stable
distribution (potato) and in version 1.1-11-8 for the unstable
distribution (sid).

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)

Family: Debian Local Security Checks

Nessus Plugin ID: 15021 (debian_DSA-184.nasl)

Bugtraq ID:

CVE ID: CVE-2002-1235