[30352] in Kerberos
RE: ZDNet UK: Kerberos harbours critical flaws
daemon@ATHENA.MIT.EDU (Paul Moore)
Mon Oct 13 12:37:25 2008
Content-class: urn:content-classes:message
MIME-Version: 1.0
Date: Mon, 13 Oct 2008 09:36:35 -0700
Message-ID: <BB7E16A14DE689469A181EC770AFBF4D021FE703@exch-one.centrify.com>
In-Reply-To: <49679D29-C531-48B4-B802-D8E689DAEECA@mit.edu>
From: "Paul Moore" <paul.moore@centrify.com>
To: "Ken Raeburn" <raeburn@mit.edu>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
oops - i didnt notice the date. For some reason my automated alert
system picked it up. Thx
-----Original Message-----
From: Ken Raeburn [mailto:raeburn@MIT.EDU]
Sent: Monday, October 13, 2008 9:33 AM
To: Paul Moore
Cc: kerberos@mit.edu
Subject: Re: ZDNet UK: Kerberos harbours critical flaws
On Oct 13, 2008, at 12:23, Paul Moore wrote:
> Which bugs is this article referring to
>
> ------------------------------------------------------------
> http://news.zdnet.co.uk/security/0,1000000189,39165276,00.htm
>
> Kerberos harbours critical flaws
>
> The network-authentication technology can leave computers running
> Unix, Linux
> or Mac OS X vulnerable
They mention double-free problems, and the article is from September
2004, so I expect it's referring to the flaw in advisory MITKRB5-
SA-2004-002 (listed at http://web.mit.edu/kerberos/advisories/) which
had come out a few days before.
Ken
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos