exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2006.139

Mandriva Linux Security Advisory 2006.139
Posted Aug 27, 2006
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory MDKSA-2006-139 - A flaw was discovered in some bundled Kerberos-aware packages that would fail to check the results of the setuid() call. This call can fail in some circumstances on the Linux 2.6 kernel if certain user limits are reached, which could be abused by a local attacker to get the applications to continue to run as root, possibly leading to an elevation of privilege.

tags | advisory, kernel, local, root
systems | linux, mandriva
advisories | CVE-2006-3083
SHA-256 | f029b2aa00bed2d9f30dd82c9b39ee984241d7c19daea742e84df081598b0ebe

Mandriva Linux Security Advisory 2006.139

Change Mirror Download

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2006:139
http://www.mandriva.com/security/
_______________________________________________________________________

Package : krb5
Date : September 9, 2006
Affected: 2006.0, Corporate 3.0, Multi Network Firewall 2.0
_______________________________________________________________________

Problem Description:

A flaw was discovered in some bundled Kerberos-aware packages that
would fail to check the results of the setuid() call. This call can
fail in some circumstances on the Linux 2.6 kernel if certain user
limits are reached, which could be abused by a local attacker to get
the applications to continue to run as root, possibly leading to an
elevation of privilege.

Updated packages have been patched to correct this issue.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3083
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2006.0:
9769771585fb7b7fc6cf6feea1d6852d 2006.0/RPMS/ftp-client-krb5-1.4.2-1.1.20060mdk.i586.rpm
132d70eb7cc47ac787ceb4490f87d308 2006.0/RPMS/ftp-server-krb5-1.4.2-1.1.20060mdk.i586.rpm
ebcf417d249dc28511c8e6579ad832de 2006.0/RPMS/krb5-server-1.4.2-1.1.20060mdk.i586.rpm
37eb990906dea9b113f8dde526a218ab 2006.0/RPMS/krb5-workstation-1.4.2-1.1.20060mdk.i586.rpm
12bd0420fdfdf55433beaa839d245c7d 2006.0/RPMS/libkrb53-1.4.2-1.1.20060mdk.i586.rpm
73ec87553b0dfdee4170c23fd42f9b33 2006.0/RPMS/libkrb53-devel-1.4.2-1.1.20060mdk.i586.rpm
2e9bca676a7c89a2970105ec73dfd43a 2006.0/RPMS/telnet-client-krb5-1.4.2-1.1.20060mdk.i586.rpm
309990a6c12954d0c742ae3fcc20d3f7 2006.0/RPMS/telnet-server-krb5-1.4.2-1.1.20060mdk.i586.rpm
6b8f5083efd5c04230fb732636e78269 2006.0/SRPMS/krb5-1.4.2-1.1.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
7379da32042912507b45257c3ae7527a x86_64/2006.0/RPMS/ftp-client-krb5-1.4.2-1.1.20060mdk.x86_64.rpm
5b9c39f00856cbfe56c984636c9616ec x86_64/2006.0/RPMS/ftp-server-krb5-1.4.2-1.1.20060mdk.x86_64.rpm
dcbd8eb16edbaeab7f96bbbd61a63a42 x86_64/2006.0/RPMS/krb5-server-1.4.2-1.1.20060mdk.x86_64.rpm
27f81fe2c23b1aadb77bf36a765f1f3a x86_64/2006.0/RPMS/krb5-workstation-1.4.2-1.1.20060mdk.x86_64.rpm
3ab0d3234686c559c0ca1363503f6632 x86_64/2006.0/RPMS/lib64krb53-1.4.2-1.1.20060mdk.x86_64.rpm
b79453018b1fdfd10cd1e67ed77eeecb x86_64/2006.0/RPMS/lib64krb53-devel-1.4.2-1.1.20060mdk.x86_64.rpm
7ec7ec461afca7f7707e010310be4532 x86_64/2006.0/RPMS/telnet-client-krb5-1.4.2-1.1.20060mdk.x86_64.rpm
e596730793941a4aedb582abb7bec0cf x86_64/2006.0/RPMS/telnet-server-krb5-1.4.2-1.1.20060mdk.x86_64.rpm
6b8f5083efd5c04230fb732636e78269 x86_64/2006.0/SRPMS/krb5-1.4.2-1.1.20060mdk.src.rpm

Corporate 3.0:
828af711a7bc04cee4de3fccba07543f corporate/3.0/RPMS/ftp-client-krb5-1.3-6.7.C30mdk.i586.rpm
fc41fbc471acd1d94716ba7b37094e2c corporate/3.0/RPMS/ftp-server-krb5-1.3-6.7.C30mdk.i586.rpm
d118695919843b28dc401994b2f8605f corporate/3.0/RPMS/krb5-server-1.3-6.7.C30mdk.i586.rpm
c75c0d61e7fc98123f4dbfce2b2d3109 corporate/3.0/RPMS/krb5-workstation-1.3-6.7.C30mdk.i586.rpm
156f7354acd35590c33903d5dce0697d corporate/3.0/RPMS/libkrb51-1.3-6.7.C30mdk.i586.rpm
15c4329696fbcfecc7bedc62c56cf577 corporate/3.0/RPMS/libkrb51-devel-1.3-6.7.C30mdk.i586.rpm
d88d3533f6993057eb01d9baeb8f9046 corporate/3.0/RPMS/telnet-client-krb5-1.3-6.7.C30mdk.i586.rpm
be90de149ade08f77bf15481e4a65bf6 corporate/3.0/RPMS/telnet-server-krb5-1.3-6.7.C30mdk.i586.rpm
b5ab69f2c45bd7fd8ddf24204126a0d1 corporate/3.0/SRPMS/krb5-1.3-6.7.C30mdk.src.rpm

Corporate 3.0/X86_64:
52e38def3585a04f2cec5dff30d1dad2 x86_64/corporate/3.0/RPMS/ftp-client-krb5-1.3-6.7.C30mdk.x86_64.rpm
02a6c33fc49fe58013e999e2a4773f70 x86_64/corporate/3.0/RPMS/ftp-server-krb5-1.3-6.7.C30mdk.x86_64.rpm
c3a9e4068740aeb23667ed5d46f0b48d x86_64/corporate/3.0/RPMS/krb5-server-1.3-6.7.C30mdk.x86_64.rpm
9196af8c916c889cbe234acb1393faf0 x86_64/corporate/3.0/RPMS/krb5-workstation-1.3-6.7.C30mdk.x86_64.rpm
ae7336d754a485b4f24a42f3c36fbb59 x86_64/corporate/3.0/RPMS/lib64krb51-1.3-6.7.C30mdk.x86_64.rpm
d38b0395a79d4ea909aeaf0eefcdc9d4 x86_64/corporate/3.0/RPMS/lib64krb51-devel-1.3-6.7.C30mdk.x86_64.rpm
9e9bc222b2d7cbfc47c1af0fabd6ffd5 x86_64/corporate/3.0/RPMS/telnet-client-krb5-1.3-6.7.C30mdk.x86_64.rpm
afd4f60af3022e6c319eb38fb658ca24 x86_64/corporate/3.0/RPMS/telnet-server-krb5-1.3-6.7.C30mdk.x86_64.rpm
b5ab69f2c45bd7fd8ddf24204126a0d1 x86_64/corporate/3.0/SRPMS/krb5-1.3-6.7.C30mdk.src.rpm

Multi Network Firewall 2.0:
99da07eef578ea9634378d30310ea6da mnf/2.0/RPMS/libkrb51-1.3-6.7.M20mdk.i586.rpm
8fd9018ab4c3bed69af2466a5e587f25 mnf/2.0/SRPMS/krb5-1.3-6.7.M20mdk.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFE2hBLmqjQ0CJFipgRAos9AKC0mteYb2PDP8yhuU0LsgFtlkTCDgCgk2xi
d/ocXoroUAfnEQeE1BGP8LM=
=+vtq
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close