Security Vulnerability in RPCSEC_GSS (rpcsec_gss(3NSL)) Affects Kerberos Administration Daemon (kadmind(1M))



Category :Security
Release Phase :Resolved
Product :Solaris 9 Operating System
Solaris 10 Operating System
Solaris 8 Operating System  
Bug Id :6591024  
Date of Workaround Release :05-SEP-2007 
Date of Resolved Release :22-OCT-2007 


Impact

A stack overflow vulnerability in the RPCSEC_GSS (see rpcsec_gss(3NSL)) security flavor used to access the Generic Security Services Application Programming Interface (GSS-API) affects the Kerberos administration daemon (kadmind(1M)). This vulnerability may allow an unauthorized remote user the ability to execute arbitrary commands on Kerberos Key Distribution Center(KDC) systems with the privileges of the kadmind(1M) daemon (usually root). This may also allow the remote user to compromise the Kerberos key database or cause the kadmind(1M) daemon to crash, which is a type of Denial of Service (DoS).

Note: Third-party applications which utilize RPCSEC_GSS may also be affected.

This issue is also referenced in the following documents:

MITKRB5-SA-2007-006 at:

CVE-2007-3999 at:

Note: Solaris is not affected by CVE-2007-4000 mentioned in MITKRB5-SA-2007-006.


Contributing Factors

This issue can occur in the following releases:

SPARC Platform

x86 Platform

Note: This issue only occurs if the system is configured as a Key Distribution Center (KDC).

To determine if the system is configured as a Key Distribution Center, the following command can be used:

    % pgrep -l kadmind
    938 kadmind

If the above command shows a process id, the daemon kadmind(1M) is running and the machine is configured as the Key Distribution Center (KDC).


Symptoms

There are no predictable symptoms that would indicate the described vulnerability has been exploited.


Workaround

There is no workaround.  Please see the Resolution section below.


Resolution

This issue is addressed in the following releases:

SPARC Platform

x86 Platform




Modification History


Date: 10-OCT-2007
  • Updated Relief/Workaround section

Date: 16-OCT-2007
  • Updated Contributing Factors, Relief/Workaround, and Resolution sections

Date: 22-OCT-2007
  • State: Resolved
  • Updated Contributing Factors and Resolution sections



Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 201319
Article Type : Sun Alert
Last reviewed : 2007-10-22
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article