OpenBSD Journal

ZDNet Boo Boo & Kerberos Vulnerabilities

Contributed by Dengue on from the don't-get-all-excited dept.

A news story on ZDnet incorrectly claimed that OpenBSD was affected by a recent vulnerability in MIT Kerberos. It turns out that OpenBSD uses KTH's implementation which is not affected, per Hans Insulander's post to the announce@openbsd mailing list. Besides, MIT's code isn't exportable without ripping out all the crypto code.

ZDnet was notified of the error and they made the correction within minutes.

(Comments are closed)

  1. By Amanda () on

    I think that your information is dated from the last century. MIT Kerberos is now being exported with every copy of RedHat Linux. Full strength Kerberos is also available world wide in Windows 2000.


Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]