Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance News & Announcements
  • Search

[gentoo-security] GLSA: openafs (200303-26)

Read this before submitting your first post to any forum
Post Reply
Advanced search
1 post • Page 1 of 1
Author
Message
pjp
Administrator
Administrator
User avatar
Posts: 20668
Joined: Tue Apr 16, 2002 10:35 pm

[gentoo-security] GLSA: openafs (200303-26)

  • Quote

Post by pjp » Mon Mar 31, 2003 4:48 pm

Daniel Ahlberg wrote:- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-26
- - ---------------------------------------------------------------------

PACKAGE : openafs
SUMMARY : cryptographic weakness in Kerberos v4
DATE : 2003-03-30 15:50 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <1.3.2-r1
FIXED VERSION : >=1.3.2-r1
CVE : CAN-2003-0139

- - ---------------------------------------------------------------------

- From advisory:
"A cryptographic weakness in version 4 of the Kerberos protocol allows an
attacker to use a chosen-plaintext attack to impersonate any principal in a
realm. OpenAFS kaserver implements version 4 of the Kerberos protocol, and
therefore is vulnerable. An attacker that knows a shared cross-realm key
between any remote realm and the local realm can impersonate any principal in
the local realm to AFS database servers and file servers in the local cell,
and other services in the local realm. An attacker that can create arbitrary
principal names in a realm can also impersonate any principal in that realm."

Read the full advisory at
http://www.openafs.org/pages/security/O ... 03-001.txt

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-fs/openafs upgrade to openafs-1.3.2-r1 as follows:

emerge sync
emerge openafs
emerge clean

- - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz
rphillips@gentoo.org
- - ---------------------------------------------------------------------
Mailing List Archive: Unavailable
Quis separabit? Quo animo?
Top
Post Reply
1 post • Page 1 of 1

Return to “News & Announcements”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic