PT-2001-1046 · Mit+2 · Krb5-Devel+9

Riley Hassell

·

Published

2001-08-02

·

Updated

2020-01-21

·

CVE-2003-0028

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.1.3 through 2.2.4 krb5-workstation versions 1.1.1 through 1.2.7 krb5-server versions 1.1.1 through 1.2.7 krb5-devel versions 1.1.1 through 1.2.7 krb5-libs versions 1.1.1 through 1.2.7 krb5 versions 1.1.1 through 1.2.7 glibc-common version 2.2.4 glibc-profile versions 2.1.3 through 2.2.4 glibc-devel versions 2.1.3 through 2.2.4
Description The issue is related to multiple vulnerabilities in various packages of the Red Hat Linux operating system, including glibc and krb5. These vulnerabilities can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information. The vulnerabilities are related to integer overflows in certain functions, which can allow remote attackers to execute arbitrary code.
Recommendations For glibc versions 2.1.3 through 2.2.4, update to a version that is not affected by the vulnerability. For krb5-workstation versions 1.1.1 through 1.2.7, update to a version that is not affected by the vulnerability. For krb5-server versions 1.1.1 through 1.2.7, update to a version that is not affected by the vulnerability. For krb5-devel versions 1.1.1 through 1.2.7, update to a version that is not affected by the vulnerability. For krb5-libs versions 1.1.1 through 1.2.7, update to a version that is not affected by the vulnerability. For krb5 versions 1.1.1 through 1.2.7, update to a version that is not affected by the vulnerability. For glibc-common version 2.2.4, update to a version that is not affected by the vulnerability. For glibc-profile versions 2.1.3 through 2.2.4, update to a version that is not affected by the vulnerability. For glibc-devel versions 2.1.3 through 2.2.4, update to a version that is not affected by the vulnerability. As a temporary workaround, consider restricting access to the vulnerable functions until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07993
BDU:2015-07994
BDU:2015-07997
BDU:2015-08004
BDU:2015-08005
BDU:2015-08008
BDU:2015-08009
BDU:2015-08132
BDU:2015-08133
BDU:2015-08134
BDU:2015-08135
BDU:2015-08136
BDU:2015-08137
BDU:2015-08138
BDU:2015-08139
BDU:2015-08141
BDU:2015-08142
BDU:2015-08143
BDU:2015-08144
BDU:2015-08145
BDU:2015-08146
BDU:2015-08147
CVE-2003-0028
DSA-266
DSA-272
DSA-282

Affected Products

Red Hat
Glibc
Glibc-Common
Glibc-Devel
Glibc-Profile
Krb5
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation