USN-1116-1: Kerberos vulnerability
19 April 2011
An unauthenticated remote user could crash the Kerberos service.
Releases
Packages
- krb5 - MIT Kerberos services
Details
Felipe Ortega discovered that kadmind did not correctly handle password
changing error conditions. An unauthenticated remote attacker could exploit
this to crash kadmind, leading to a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 10.10
Ubuntu 10.04
In general, a standard system update will make all the necessary changes.