[2488] in Kerberos

home help back first fref pref prev next nref lref last post

If you are running a Kerberos V4 server, PLEASE APPLY THIS PATCH

daemon@ATHENA.MIT.EDU (Theodore Ts'o)
Wed Dec 30 16:28:18 1992

Date: Wed, 30 Dec 92 16:11:32 EST
From: tytso@ATHENA.MIT.EDU (Theodore Ts'o)
To: kerberos@MIT.EDU

We have recently discovered a problem in the V4 Kerberos server; it was
not properly checking the string lengths of the principal names in
incoming requests.  On certain architectures, this will cause the
in-core master key schedule to be overwritten, causing the KDC to fail
by sending out garbage instead of tickets in response to requests, thus
resulting in a fairly nasty denial-of-service attack.

I strongly urge you to apply the following patch to your V4 kerberos
servers.

						- Ted

System: Kerberos V4, any patch level
Priority: MEDIUM-HIGH

*** /tmp/,RCSt1a05375	Thu Dec 17 19:25:15 1992
--- kerberos.c	Thu Dec 17 18:57:33 1992
***************
*** 317,322 ****
--- 317,323 ----
      }
  }
  
+ #define LENGTH_CHECK(str, size) if (strlen((str)) >= (size)) (str)[(size)-1]=0
  
  kerberos(client, pkt)
      struct sockaddr_in *client;
***************
*** 392,399 ****
--- 393,403 ----
  
  	    /* set up and correct for byte order and alignment */
  	    req_name_ptr = (char *) pkt_a_name(pkt);
+ 	    LENGTH_CHECK(req_name_ptr, ANAME_SZ);
  	    req_inst_ptr = (char *) pkt_a_inst(pkt);
+ 	    LENGTH_CHECK(req_inst_ptr, INST_SZ);
  	    req_realm_ptr = (char *) pkt_a_realm(pkt);
+ 	    LENGTH_CHECK(req_realm_ptr, REALM_SZ);
  	    bcopy(pkt_time_ws(pkt), &req_time_ws, sizeof(req_time_ws));
  	    /* time has to be diddled */
  	    if (swap_bytes) {
***************
*** 404,410 ****
--- 408,416 ----
  	    req_life = (u_long) (*ptr++);
  
  	    service = ptr;
+ 	    LENGTH_CHECK(service, SNAME_SZ);
  	    instance = ptr + strlen(service) + 1;
+ 	    LENGTH_CHECK(instance, INST_SZ);
  
  	    rpkt = &rpkt_st;
  	    klog(L_INI_REQ,
***************
*** 528,534 ****
--- 534,542 ----
  	    req_life = (u_long) (*ptr++);
  
  	    service = ptr;
+ 	    LENGTH_CHECK(service, SNAME_SZ);
  	    instance = ptr + strlen(service) + 1;
+ 	    LENGTH_CHECK(instance, INST_SZ);
  
  	    klog(L_APPL_REQ, "APPL Request %s.%s@%s on %s for %s.%s",
  	     ad->pname, ad->pinst, ad->prealm, inet_ntoa(client_host),

home help back first fref pref prev next nref lref last post