version 1.10, 2004/05/30 22:40:51 |
version 1.11, 2004/05/31 17:23:05 |
|
|
<li><a name="kerberos"></a> |
<li><a name="kerberos"></a> |
<font color="#00900"><strong>022: SECURITY FIX: May 30, |
<font color="#00900"><strong>022: SECURITY FIX: May 30, |
2004</strong></font><br> |
2004</strong></font><br> |
A flaw in the Kerberos V <A |
A flaw in the Kerberos V <a |
HREF="http://www.openbsd.org/cgi-bin/man.cgi?query=kdc">kdc(8)</a> |
href="http://www.openbsd.org/cgi-bin/man.cgi?query=kdc">kdc(8)</a> |
server could result in the administrator of a Kerberos realm having |
server could result in the administrator of a Kerberos realm having |
the ability to impersonate any principal in any other realm which |
the ability to impersonate any principal in any other realm which |
has established a cross-realm trust with their realm. The flaw is due to |
has established a cross-realm trust with their realm. The flaw is due to |
inadequate checking of the "transited" field in a Kerberos request. For |
inadequate checking of the "transited" field in a Kerberos request. For |
more details see <A HREF="http://www.pdc.kth.se/heimdal/advisory/2004-04-01/"> |
more details see <a href="http://www.pdc.kth.se/heimdal/advisory/2004-04-01/"> |
Heimdal's announcement</A>. |
Heimdal's announcement</A>. |
<br> |
<br> |
<a |
<a |