Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
Date: Fri Apr 05 2013 - 09:02:00 CDT
-----BEGIN PGP SIGNED MESSAGE-----
Mandriva Linux Security Advisory MDVSA-2013:042
Package : krb5
Date : April 5, 2013
Affected: Business Server 1.0
Multiple vulnerabilities has been discovered and corrected in krb5:
Fix a kadmind denial of service issue (null pointer dereference),
which could only be triggered by an administrator with the create
The MIT krb5 KDC (Key Distribution Center) daemon can free an
uninitialized pointer while processing an unusual AS-REQ, corrupting
the process heap and possibly causing the daemon to abnormally
terminate. An attacker could use this vulnerability to execute
malicious code, but exploiting frees of uninitialized pointers to
execute code is believed to be difficult. It is possible that a
legitimate client that is misconfigured in an unusual way could
trigger this vulnerability (CVE-2012-1015).
It was reported that the KDC plugin for PKINIT could dereference a
NULL pointer when a malformed packet caused processing to terminate
early, which led to a crash of the KDC process. An attacker would
require a valid PKINIT certificate or have observed a successful
PKINIT authentication to execute a successful attack. In addition,
an unauthenticated attacker could execute the attack of anonymouse
PKINIT was enabled (CVE-2013-1415).
The updated packages have been patched to correct these issues.
Mandriva Business Server 1/X86_64:
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
If you want to report vulnerabilities, please contact
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
-----END PGP SIGNATURE-----
Content-Type: text/plain; charset="UTF-8"; name="message-footer.txt"
Content-Disposition: inline; filename="message-footer.txt"
To unsubscribe, send a email to sympamandrivalinux.org
with this subject : unsubscribe security-announce
Want to buy your Pack or Services from Mandriva?
Go to http://store.mandriva.com