Security Update: MIT Kerberos
SECURITY UPDATE:
The MIT Kerberos Development Team has released MIT krb5 Security Advisory 2008-002 to address vulnerabilities in multiple versions of MIT Kerberos. Potential consequences include arbitrary code execution, key database compromise, and denial of service.
For detailed descriptions, please refer to MIT Security Advisory 2008-002.
AFFECTED SOFTWARE:
*MIT Kerberos
WHAT YOU NEED TO DO TO PROTECT YOUR SYSTEM:
Install updates from your vendor
1. Do NOT take action if you have a Computer Support Coordinator (CSC); s/he will apply the update for you or assist in instructing you.
2. If you do not have a CSC, check with your vendors for patches or updates. Administrators who compile MIT Kerberos from source should refer to MIT Security Advisory 2008-002 for more information.
ADDITIONAL INFORMATION:
Enterprise Information Security
US-CERT Technical Cyber Security Alert TA08-079B
http://www.us-cert.gov/cas/techalerts/TA08-079B.html
Customer Support
Office of Academic & Administrative
Information Systems (OAAIS)
7 a.m. - 6 p.m., Mon – Fri
(415) 514-4100, option 2
CustomerSupport@ucsf.edu
