OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: BUFFER OVERRUN VULNERABILITIES IN KERBEROS
From: Assar Westerlund (assarSICS.SE)
Date: Tue May 16 2000 - 17:59:16 CDT


"Jeffrey I. Schiller" <jisMIT.EDU> writes:
> BUFFER OVERRUN VULNERABILITIES IN KERBEROS

[ ... ]

> VULNERABLE DISTRIBUTIONS AND PROGRAMS:
>
> Source distributions which may contain vulnerable code include:
>
> MIT Kerberos 5 releases krb5-1.0.x, krb5-1.1, krb5-1.1.1
>
> MIT Kerberos 4 patch 10, and likely earlier releases as well
>
> KerbNet (Cygnus implementation of Kerberos 5)
>
> Cygnus Network Security (CNS -- Cygnus implementation of
> Kerberos 4)

I would just like to add that neither of these distributions are
vulnerable:

        KTH krb4
        KTH Heimdal

/assar