Index: vuln.xml =================================================================== RCS file: /home/pcvs/ports/security/vuxml/vuln.xml,v retrieving revision 1.2140 diff -u -r1.2140 vuln.xml --- vuln.xml 18 Apr 2010 19:00:29 -0000 1.2140 +++ vuln.xml 18 Apr 2010 19:16:49 -0000 @@ -34,6 +34,79 @@ --> + + krb5 -- remote denial of service vulnerability + + + krb5 + 1.6.3_9 + + + + +

An authenticated remote attacker can causing a denial + of service by using a newer version of the kadmin protocol + than the server supports.

+

The MIT Kerberos team also reports the cause:

+
+

The Kerberos administration daemon (kadmind) can crash + due to referencing freed memory.

+
+ +
+ + 39247 + CVE-2010-0629 + http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-003.txt + + + 2010-04-06 + 2010-04-18 + +
+ + + krb5-17 -- multiple denial of service vulnerabilities + + + krb5 + + 1.7 + 1.7_2 + + + + + +

Two vulnerabilities in kb5-17 can be used by remote + attackers in denial of service attacks. The MIT security + advisories report this as follows:

+
+

An unauthenticated remote attacker can send an invalid + request to a KDC process that will cause it to crash due + to an assertion failure, creating a denial of service.

+
+
+

An unauthenticated remote attacker could cause a GSS-API + application, including the Kerberos administration daemon + (kadmind) to crash.

+
+ +
+ + 38260 + 38904 + CVE-2010-0628 + CVE-2010-0283 + http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-001.txt + http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-002.txt + + + 2010-04-23 + 2010-04-18 + +
+ mahara -- sql injection vulnerability