NASLDB: RHSA-2010-0258: pam_krb5
General
ID: 46287
Name: RHSA-2010-0258: pam_krb5
Summary: Check for the version of the pam_krb5 packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS Temporal Vector: –
Port: 0
Family: Red Hat Local Security Checks
Type: Local
Description
Updated pam_krb5 packages that fix one security issue and various bugs are
now available for Red Hat Enterprise Linux 5.
The Red Hat Security Response Team has rated this update as having low
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.
The pam_krb5 module allows Pluggable Authentication Modules (PAM) aware
applications to use Kerberos to verify user identities by obtaining user
credentials at log in time.
A flaw was found in pam_krb5. In some non-default configurations
(specifically, those where pam_krb5 would be the first module to prompt for
a password), the text of the password prompt varied based on whether or not
the username provided was a username known to the system. A remote attacker
could use this flaw to recognize valid usernames, which would aid a
dictionary-based password guess attack. (CVE-2009-1384)
This update also fixes the following bugs:
* certain applications which do not properly implement PAM conversations
may fail to authenticate users whose passwords have expired and must be
changed, or may succeed without forcing the user\‘s password to be changed.
This bug is triggered by a previously-applied fix to pam_krb5 which makes
it comply more closely to PAM specifications. If an application misbehaves,
enabling the "chpw_prompt" option for its service should restore the old
behavior. (BZ#509092)
* pam_krb5 does not allow the user to change an expired password in cases
where the Key Distribution Center (KDC) is configured to refuse attempts to
obtain forwardable password-changing credentials. This update fixes this
issue. (BZ#489015)
* failure to verify TGT because of wrong keytab handling. (BZ#450776)
Users of pam_krb5 are advised to upgrade to these updated packages, which
resolve these issues.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2009-1384
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2010/05/11
Plugin
Version: 1.5
Filename: redhat-RHSA-2010-0258.nasl
Filesize: 3688 bytes
MD5 Hash: b12ed9e83fc88717e0f06823e657e82d
Identification: Host/RedHat/rpm-list
Require Keys: Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2010-2011 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













