Note: This is an archival copy of Security Sun Alert 256728 as previously published on http://sunsolve.sun.com. Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1020355.1. |
Category Security Release Phase Resolved 6822062, 6822066 Product Sun Enterprise Authentication Mechanism 1.0.1 Solaris 9 Operating System Solaris 10 Operating System OpenSolaris Date of Workaround Release 07-Apr-2009 Date of Resolved Release 03-Aug-2009 Multiple Security Vulnerabilities in the Solaris Kerberos 'Mech' Libraries May Lead To Execution of Arbitrary Code, Unauthorized Access to Data or a Denial of Service (DoS) Condition 1. Impact Multiple security vulnerabilities in the Solaris Kerberos (see kerberos(5)) mech_krb5 library and the mech_spnego(5) library may allow remote unprivileged users to cause certain Kerberos applications and daemons, including the Kerberos administration daemon (kadmind(1M)) to crash. These issues may also lead to unauthorized information disclosure and execution of arbitrary code with the privileges of the root user. These issues are also described in the following documents: CVE-2009-0844 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0844
CVE-2009-0845 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0845 CVE-2009-0846 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846 CVE-2009-0847 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0847 These issues are also described in the following documents: MIT Advisory MITKRB5-SA-2009-002 at http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2009-002.txt
MIT Advisory MITKRB5-SA-2009-001 at http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2009-001.txt 2. Contributing Factors CVE-2009-0844 and CVE-2009-0845 can occur only in the following releases: SPARC Platform
SPARC Platform
$ uname -vNote: This issue could affect all systems utilizing Kerberos. To determine if a system is configured to use Kerberos, the following command may be run: % grep default_realm /etc/krb5/krb5.confIf the output of the above command is as follows: default_realm = ___default_realm___then the system is not configured to use Kereberos. 3. Symptoms There are no predictable symptoms to indicate these issue have been exploited. 4. Workaround Until patches can be applied, these issues may be worked around by disabling Kerberos on the affected systems by moving the "/etc/krb5/krb5.conf file", for example: # mv /etc/krb5/krb5.conf /etc/krb5/krb5.conf.SAVE5. Resolution This issue is addressed in the following releases: SPARC Platform
This Sun Alert notification is being provided to you on an "AS IS" basis. This Sun Alert notification may contain information provided by third parties. The issues described in this Sun Alert notification may or may not impact your system(s). Sun makes no representations, warranties, or guarantees as to the information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT YOU ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. This Sun Alert notification contains Sun proprietary and confidential information. It is being provided to you pursuant to the provisions of your agreement to purchase services from Sun, or, if you do not have such an agreement, the Sun.com Terms of Use. This Sun Alert notification may only be used for the purposes contemplated by these agreements. Copyright 2000-2009 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara, CA 95054 U.S.A. All rights reserved. Modification History 08-Apr-2009: Updated Workaround section for IDRs release 19-Jun-2009: Updated Contributing Factors and Resolution sections 01-Jul-2009: Updated Contributing Factors and Resolution sections 03-Aug-2009: Updated Contributing Factors and Resolution sections; Resolved References112390-15112237-17 112240-14 112238-16 140074-08 140130-09 112908-36 115168-21 Attachments This solution has no attachment |
|