y Patches 013 and 026 address Kerb4 weakness
Contributed by jose on Mon Mar 24 19:35:00 2003 (GMT)
from the waste-not-want-not dept.
Thanks to the heads up from Todd Miller:
There is a cryptographic weaknesses in the Kerberos v4 protocol
(this is not something that is fixable in Kerberos v4). Sites still
using Kerberos v4 should migrate to Kerberos v5.
Kerberos v5 does not have this weakness, but since it contains v4
to v5 translation services it is still possible to exploit the v4
The files for
026_kerberos.patch (for 3.1-stable)
013_kerberos.patch (for 3.2-stable)
are making their way around the FTP servers. Thank you, Todd.
For more information, please see the
The following patches cause Kerberos v4 requests from foreign realms
to be ignored unless support for this is explicitly enabled ....
The aforementioned patches have already been applied to the 3.1 and
3.2 -stable branches.
<< Interesting Systrace Helpers | Reply | Flattened | Expanded | PF for FreeBSD 5.0 >>
Add Story |
Copyright © 2004-2008
All rights reserved.
Articles and comments are copyright their respective authors,
submission implies license to publish on this web site.
Contents of the archive prior to April 2nd 2004 as well as images
and HTML templates were copied from the fabulous original
Jim's kind permission.
Some icons from slashdot.org
used with permission from Kathleen.
This journal runs as CGI with
on OpenBSD, the
source code is
Search engine is ht://Dig.
undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]