Original Issue Date:November 25, 2006 Severity Rating: HIGH
Systems Affected
Overview
Description
A vulnerability has been reported in apache module mod_auth_kerb due to an off-by-one buffer overflow error in the "der_get_oid " [spnegokrb5/der_get.c] function.
Solution
Vendor Information
Kerberos Module for Apache http://modauthkerb.sourceforge.net/
References
FrSIRT- ADV-2006-4633 http://www.frsirt.com/english/advisories/2006/4633
Secunia http://secunia.com/advisories/23023/
Security Focus http://www.securityfocus.com/bid/21214
CVE Name CVE-2006-5989
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India