Mandrake Linux Security Advisory : krb5 (MDKSA-2007:077-1)

High Nessus Plugin ID 24943


The remote Mandrake Linux host is missing one or more security updates.


A vulnerability was found in the username handling of the MIT krb5 telnet daemon. A remote attacker that could access the telnet port of a target machine could login as root without requiring a password (CVE-2007-0956).

Buffer overflows in the kadmin server daemon were discovered that could be exploited by a remote attacker able to access the KDC.
Successful exploitation could allow for the execution of arbitrary code with the privileges of the KDC or kadmin server processes (CVE-2007-0957).

Finally, a double-free flaw was discovered in the GSSAPI library used by the kadmin server daemon, which could lead to a denial of service condition or the execution of arbitrary code with the privileges of the KDC or kadmin server processes (CVE-2007-1216).

Updated packages have been patched to address this issue.

Update :

Packages for Mandriva Linux 2007.1 are now available.


Update the affected packages.

See Also

Plugin Details

Severity: High

ID: 24943

File Name: mandrake_MDKSA-2007-077.nasl

Version: $Revision: 1.19 $

Type: local

Published: 2007/04/05

Modified: 2015/03/19

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 9

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:ftp-client-krb5, p-cpe:/a:mandriva:linux:ftp-server-krb5, p-cpe:/a:mandriva:linux:krb5-server, p-cpe:/a:mandriva:linux:krb5-workstation, p-cpe:/a:mandriva:linux:lib64krb53, p-cpe:/a:mandriva:linux:lib64krb53-devel, p-cpe:/a:mandriva:linux:libkrb53, p-cpe:/a:mandriva:linux:libkrb53-devel, p-cpe:/a:mandriva:linux:telnet-client-krb5, p-cpe:/a:mandriva:linux:telnet-server-krb5, cpe:/o:mandriva:linux:2007.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2007/04/10

Exploitable With

CANVAS (D2ExploitPack)

Reference Information

CVE: CVE-2007-0956, CVE-2007-0957, CVE-2007-1216

BID: 23281, 23282, 23285

MDKSA: 2007:077-1

CWE: 119