This service will be undergoing maintenance at 00:00 UTC, 2017-10-23 It is expected to last about 30 minutes
Bug 491034 - (CVE-2009-0847) CVE-2009-0847 krb5: incorrect length check inside ASN.1 decoder (MITKRB5-SA-2009-001)
CVE-2009-0847 krb5: incorrect length check inside ASN.1 decoder (MITKRB5-SA-2...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
http://web.nvd.nist.gov/view/vuln/det...
impact=important,source=upstream,repo...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2009-03-18 22:17 EDT by Vincent Danen
Modified: 2016-01-22 12:07 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2010-04-08 13:58:53 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Vincent Danen 2009-03-18 22:17:48 EDT
MIT krb5 can perform an incorrect length check inside an ASN.1
decoder.  This only presents a problem in the PK-INIT code paths.  In
the MIT krb5 KDC or kinit program, this could lead to spurious
malloc() failures or, under some conditions, program crash.  We have
heard reports of the spurious malloc() failures, but nobody has yet
made the publicly made the connection to a security issue.
Comment 2 Vincent Danen 2009-03-18 22:21:24 EDT
This issue only affects krb5 1.6.3+.  Prior releases contained the vulnerable code, but the vulnerability is masked due to operations perfomed by other code. so this does not affect Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Comment 6 Tomas Hoger 2009-04-07 14:20:59 EDT
Public now via:
  http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-001.txt
Comment 7 Fedora Update System 2009-04-07 19:23:15 EDT
krb5-1.6.3-16.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 8 Fedora Update System 2009-04-07 19:23:35 EDT
krb5-1.6.3-18.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 9 Tomas Hoger 2009-04-09 05:30:20 EDT
Even though this problem was not exposed in the krb5 versions shipped in Red Hat Enterprise Linux 2.1, 3, 4, and 5 and hence did not create a security flaw on those versions, upstream patch addressing underlying problem being part of the MITKRB5-SA-2009-001 patch was included in the updates addressing other ASN.1 decoding issue - CVE-2009-0846 and was released in following errata:
  https://rhn.redhat.com/errata/CVE-2009-0846.html
Comment 10 Red Hat Product Security 2009-04-09 05:35:48 EDT
This issue was addressed in:

Fedora:
  https://admin.fedoraproject.org/updates/F10/FEDORA-2009-2852
  https://admin.fedoraproject.org/updates/F9/FEDORA-2009-2834

Note You need to log in before you can comment on or make changes to this bug.