Bug 491034 (CVE-2009-0847)
| Summary: | CVE-2009-0847 krb5: incorrect length check inside ASN.1 decoder (MITKRB5-SA-2009-001) | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Vincent Danen <vdanen> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | nalin, rcvalle |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0847 | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2010-04-08 17:58:53 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Vincent Danen
2009-03-19 02:17:48 UTC
This issue only affects krb5 1.6.3+. Prior releases contained the vulnerable code, but the vulnerability is masked due to operations perfomed by other code. so this does not affect Red Hat Enterprise Linux 2.1, 3, 4, or 5. Public now via: http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-001.txt krb5-1.6.3-16.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report. krb5-1.6.3-18.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report. Even though this problem was not exposed in the krb5 versions shipped in Red Hat Enterprise Linux 2.1, 3, 4, and 5 and hence did not create a security flaw on those versions, upstream patch addressing underlying problem being part of the MITKRB5-SA-2009-001 patch was included in the updates addressing other ASN.1 decoding issue - CVE-2009-0846 and was released in following errata: https://rhn.redhat.com/errata/CVE-2009-0846.html This issue was addressed in: Fedora: https://admin.fedoraproject.org/updates/F10/FEDORA-2009-2852 https://admin.fedoraproject.org/updates/F9/FEDORA-2009-2834 |