NASLDB: SUSE-SA:2002:034: heimdal
General
ID: 13755
Name: SUSE-SA:2002:034: heimdal
Summary: Check for the version of the heimdal package
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: –
Family: SuSE Local Security Checks
Type: –
Description
The remote host is missing the patch for the advisory SUSE-SA:2002:034 (heimdal).
The Heimdal package is a free Kerberos implementation offering flexible
authentication mechanisms based on the Kerberos 5 and Kerberos 4 scheme.
The SUSE Security Team has reviewed critical parts of the Heimdal
package such as the kadmind and kdc server. While doing so several
possible buffer overflows and other bugs have been uncovered and fixed.
Remote attackers can probably gain remote root access on unpatched systems.
Since these services run usually on authentication servers we consider
these bugs to be very serious. An update is strongly recommended if you are
using the Heimdal package.
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command ‘rpm -Fhv file.rpm’ to apply
the update.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: –
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2004/07/25
Plugin
Version: 1.7
Filename: suse_SA_2002_034.nasl
Filesize: 3020 bytes
MD5 Hash: c95883d2203b4b40880cb03d11aedf3e
Identification: –
Require Keys: Host/SuSE/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2004-2010 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













