Heimdal: Buffer overflow vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200506-24 / heimdal |
| Release Date |
June 29, 2005 |
| Latest Revision |
June 29, 2005: 01 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| app-crypt/heimdal |
<
0.6.5 |
>=
0.6.5 |
All supported architectures
|
Related bugreports:
#96727
Synopsis
Multiple buffer overflow vulnerabilities in Heimdal's telnetd server could
allow the execution of arbitrary code.
2.
Impact Information
Background
Heimdal is a free implementation of Kerberos 5 that includes a
telnetd server.
Description
It has been reported that the "getterminaltype" function of
Heimdal's telnetd server is vulnerable to buffer overflows.
Impact
An attacker could exploit this vulnerability to execute arbitrary
code with the permission of the telnetd server program.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All users should upgrade to the latest available version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-crypt/heimdal-0.6.5"
|
4.
References
|