Novell Home

CVE-2007-5471

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2007-5471 at MITRE

Description

libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of service (daemon exit) via a GSS-TSIG request. NOTE: this issue probably affects other daemons that attempt to initialize this library within a chroot configuration or other invalid configuration.

Novell/SUSE information

Novell Bugzilla entry: 290327

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 10 SP1 for x86
SUSE Linux Enterprise Server 10 SP1 for x86
  • libgssapi >= 0.6-13.7
sles10.s390x
sled10.x86
ZYPP Patch Nr: 4280
SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T
SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T
SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit
  • libgssapi >= 0.6-13.7
  • libgssapi-32bit >= 0.6-13.7
sles10.s390x
sled10.x86
ZYPP Patch Nr: 4280
SUSE Linux Enterprise Server 10 SP1 for IPF
  • libgssapi >= 0.6-13.7
  • libgssapi-x86 >= 0.6-13.7
sles10.s390x
sled10.x86
ZYPP Patch Nr: 4280
SUSE Linux Enterprise Server 10 SP1 for IBM POWER
  • libgssapi >= 0.6-13.7
  • libgssapi-64bit >= 0.6-13.7
sles10.s390x
sled10.x86
ZYPP Patch Nr: 4280

© 2012 Novell