Scientific Linux Security Update : krb5 on SL3.x i386/x86_64
Critical Nessus Plugin ID 60563
SynopsisThe remote Scientific Linux host is missing one or more security updates.
DescriptionAn input validation flaw was found in the ASN.1 (Abstract Syntax Notation One) decoder used by MIT Kerberos. A remote attacker could use this flaw to crash a network service using the MIT Kerberos library, such as kadmind or krb5kdc, by causing it to dereference or free an uninitialized pointer or, possibly, execute arbitrary code with the privileges of the user running the service. (CVE-2009-0846)
All running services using the MIT Kerberos libraries must be restarted for the update to take effect.
SolutionUpdate the affected packages.