漏洞类别:Amazon Linux
漏洞等级:
漏洞信息
A NULL pointer dereference flaw was found in MIT Kerberos kadmind service. An authenticated attacker with permission to modify a principal entry could use this flaw to cause kadmind to dereference a null pointer and crash by supplying an empty DB argument to the modify_principal command, if kadmind was configured to use the LDAP KDB module. (CVE-2016-3119 )
漏洞危害
Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.
解决方案
Please refer to Amazon advisory ALAS-2017-793 for affected packages and patching details, or update with your package manager.
Patch:
Following are links for downloading patches to fix the vulnerabilities:
ALAS-2017-793: Amazon Linux (krb5 (1.14.1-27.41.amzn1) on i686)
ALAS-2017-793: Amazon Linux (krb5 (1.14.1-27.41.amzn1) on x86_64)
ALAS-2017-793: Amazon Linux (krb5 (1.14.1-27.41.amzn1) on src)
0day
文章评论