krb5 보안 업데이트
Web Browser 로는 FTP 접속이 불가능 합니다.
문서번호 : 1264350821
업데이트 : 2010.01.25
상세내용
1.3.4-62.el4.1 update
- fixed CVE-2009-4212
CVE-2009-4212:
Multiple integer underflows in the (1) AES and (2) RC4 decryption
functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3
through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause
a denial of service (daemon crash) or possibly execute arbitrary code
by providing ciphertext with a length that is too short to be valid.
Autoupdates 지원 : Packages System
pkgadd -F "krb5*"
update 패키지
RPMS :
. krb5-libs-1.3.4-62.el4.1.i686.rpm
. krb5-server-1.3.4-62.el4.1.i686.rpm
. krb5-workstation-1.3.4-62.el4.1.i686.rpm
. krb5-devel-1.3.4-62.el4.1.i686.rpm
SRPMS :
. krb5-1.3.4-62.el4.1.src.rpm
참고 :
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4212
|