Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2007:0858 - Security Advisory
Issued:
2007-09-04
Updated:
2007-09-04

RHSA-2007:0858 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: krb5 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated krb5 packages that fix two security flaws are now available for
Red Hat Enterprise Linux 5.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

Description

Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC. kadmind is the KADM5 administration
server.

Tenable Network Security discovered a stack buffer overflow flaw in the RPC
library used by kadmind. A remote unauthenticated attacker who can access
kadmind could trigger this flaw and cause kadmind to crash. On Red Hat
Enterprise Linux 5 it is not possible to exploit this flaw to run arbitrary
code as the overflow is blocked by FORTIFY_SOURCE. (CVE-2007-3999)

Garrett Wollman discovered an uninitialized pointer flaw in kadmind. A
remote unauthenticated attacker who can access kadmind could trigger this
flaw and cause kadmind to crash. (CVE-2007-4000)

These issues did not affect the versions of Kerberos distributed with Red
Hat Enterprise Linux 2.1, 3, or 4.

Users of krb5-server are advised to update to these erratum packages which
contain backported fixes to correct these issues.

Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Affected Products

  • Red Hat Enterprise Linux Server 5 x86_64
  • Red Hat Enterprise Linux Server 5 ia64
  • Red Hat Enterprise Linux Server 5 i386
  • Red Hat Enterprise Linux Workstation 5 x86_64
  • Red Hat Enterprise Linux Workstation 5 i386
  • Red Hat Enterprise Linux Desktop 5 x86_64
  • Red Hat Enterprise Linux Desktop 5 i386
  • Red Hat Enterprise Linux for IBM z Systems 5 s390x
  • Red Hat Enterprise Linux for Power, big endian 5 ppc
  • Red Hat Enterprise Linux Server from RHUI 5 x86_64
  • Red Hat Enterprise Linux Server from RHUI 5 i386

Fixes

  • BZ - 250973 - CVE-2007-3999 krb5 RPC library buffer overflow
  • BZ - 250976 - CVE-2007-4000 krb5 kadmind uninitialized pointer

CVEs

  • CVE-2007-4000
  • CVE-2007-3999

References

  • http://www.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 5

SRPM
krb5-1.5-28.src.rpm SHA-256: 86fbccd1567abc2cb9e0e3c910391d6837618cb1a215028a631eb2b4a1b7572c
x86_64
krb5-devel-1.5-28.i386.rpm SHA-256: 5e6c38319f20e6fb8c4fc0f4dc38fca98af9c90c834506f12c51136fb73c2235
krb5-devel-1.5-28.x86_64.rpm SHA-256: 11aab738d496e60398c5497095ab17a3c30f8392557acd2ad551560b96acca9b
krb5-libs-1.5-28.i386.rpm SHA-256: 0d38f85c66c224d1b1c764457c9ce3e216bcfa992ba5e7b9ca8256e99d4491fd
krb5-libs-1.5-28.x86_64.rpm SHA-256: 723083d535f0dd795e9cf049e59b5c466e34403c0844895e9d805fe02ab78359
krb5-server-1.5-28.x86_64.rpm SHA-256: 479e40dcb2bfc7f627f4d6de84f2209f7e3f5b8be087328938f251553f89e4f4
krb5-workstation-1.5-28.x86_64.rpm SHA-256: dcca945c41a8d0aa02209d1f717de1024abf1228371d03cc43a51b05de420fd6
ia64
krb5-devel-1.5-28.ia64.rpm SHA-256: dc2c046150627ac7340f664952b6b3c839c2f520330dd0005797150c21c08d1e
krb5-libs-1.5-28.i386.rpm SHA-256: 0d38f85c66c224d1b1c764457c9ce3e216bcfa992ba5e7b9ca8256e99d4491fd
krb5-libs-1.5-28.ia64.rpm SHA-256: e10dc8d6ff0256e8d5fc1ad35712076c329f32e3ed9a0114f38fb8196a97e054
krb5-server-1.5-28.ia64.rpm SHA-256: 4e7959a24ef2e3a3c548d6106b7289e7f5aba2d14096d0fdfeb5257967a76b73
krb5-workstation-1.5-28.ia64.rpm SHA-256: 5cac01f6554e84662ac5daa97226818e07a3beb2c08fcbe7fc8e99793b5ffab6
i386
krb5-devel-1.5-28.i386.rpm SHA-256: 5e6c38319f20e6fb8c4fc0f4dc38fca98af9c90c834506f12c51136fb73c2235
krb5-libs-1.5-28.i386.rpm SHA-256: 0d38f85c66c224d1b1c764457c9ce3e216bcfa992ba5e7b9ca8256e99d4491fd
krb5-server-1.5-28.i386.rpm SHA-256: 322272fbf0625b8db7ef2c61768f726c512709daa91dd8c0ba295c498a0a1c9f
krb5-workstation-1.5-28.i386.rpm SHA-256: 324917b73734f02a121b9faa2de27dc1632c5adad138cd78d94f4d151875a1f5

Red Hat Enterprise Linux Workstation 5

SRPM
krb5-1.5-28.src.rpm SHA-256: 86fbccd1567abc2cb9e0e3c910391d6837618cb1a215028a631eb2b4a1b7572c
x86_64
krb5-devel-1.5-28.i386.rpm SHA-256: 5e6c38319f20e6fb8c4fc0f4dc38fca98af9c90c834506f12c51136fb73c2235
krb5-devel-1.5-28.x86_64.rpm SHA-256: 11aab738d496e60398c5497095ab17a3c30f8392557acd2ad551560b96acca9b
krb5-libs-1.5-28.i386.rpm SHA-256: 0d38f85c66c224d1b1c764457c9ce3e216bcfa992ba5e7b9ca8256e99d4491fd
krb5-libs-1.5-28.x86_64.rpm SHA-256: 723083d535f0dd795e9cf049e59b5c466e34403c0844895e9d805fe02ab78359
krb5-server-1.5-28.x86_64.rpm SHA-256: 479e40dcb2bfc7f627f4d6de84f2209f7e3f5b8be087328938f251553f89e4f4
krb5-workstation-1.5-28.x86_64.rpm SHA-256: dcca945c41a8d0aa02209d1f717de1024abf1228371d03cc43a51b05de420fd6
i386
krb5-devel-1.5-28.i386.rpm SHA-256: 5e6c38319f20e6fb8c4fc0f4dc38fca98af9c90c834506f12c51136fb73c2235
krb5-libs-1.5-28.i386.rpm SHA-256: 0d38f85c66c224d1b1c764457c9ce3e216bcfa992ba5e7b9ca8256e99d4491fd
krb5-server-1.5-28.i386.rpm SHA-256: 322272fbf0625b8db7ef2c61768f726c512709daa91dd8c0ba295c498a0a1c9f
krb5-workstation-1.5-28.i386.rpm SHA-256: 324917b73734f02a121b9faa2de27dc1632c5adad138cd78d94f4d151875a1f5

Red Hat Enterprise Linux Desktop 5

SRPM
krb5-1.5-28.src.rpm SHA-256: 86fbccd1567abc2cb9e0e3c910391d6837618cb1a215028a631eb2b4a1b7572c
x86_64
krb5-libs-1.5-28.i386.rpm SHA-256: 0d38f85c66c224d1b1c764457c9ce3e216bcfa992ba5e7b9ca8256e99d4491fd
krb5-libs-1.5-28.x86_64.rpm SHA-256: 723083d535f0dd795e9cf049e59b5c466e34403c0844895e9d805fe02ab78359
krb5-workstation-1.5-28.x86_64.rpm SHA-256: dcca945c41a8d0aa02209d1f717de1024abf1228371d03cc43a51b05de420fd6
i386
krb5-libs-1.5-28.i386.rpm SHA-256: 0d38f85c66c224d1b1c764457c9ce3e216bcfa992ba5e7b9ca8256e99d4491fd
krb5-workstation-1.5-28.i386.rpm SHA-256: 324917b73734f02a121b9faa2de27dc1632c5adad138cd78d94f4d151875a1f5

Red Hat Enterprise Linux for IBM z Systems 5

SRPM
krb5-1.5-28.src.rpm SHA-256: 86fbccd1567abc2cb9e0e3c910391d6837618cb1a215028a631eb2b4a1b7572c
s390x
krb5-devel-1.5-28.s390.rpm SHA-256: a3beb96c4ef722e1b797c13f936902d9c9221b05423a6305ddd9059b4f338aca
krb5-devel-1.5-28.s390x.rpm SHA-256: 8a6c3f7f6e161743be38670387d3a11e30251136f1d98c35c60848a26ebd50d3
krb5-libs-1.5-28.s390.rpm SHA-256: fae077ad4688ba60d1ac055f1bd1c981009ce7e20761905b24eae3ca20848347
krb5-libs-1.5-28.s390x.rpm SHA-256: ed1b7dd586843bf9c3ad80c01bebe630f7bdf11f2bf3443938cf7d8ddde36591
krb5-server-1.5-28.s390x.rpm SHA-256: 7201617554fbc5d79507ef8b6615bd162470f8a56bbaf89a2ca6a35291de132a
krb5-workstation-1.5-28.s390x.rpm SHA-256: acd0bfa59241accab04102ab4a334e3556af45c6c7ee610e1916421b32c37122

Red Hat Enterprise Linux for Power, big endian 5

SRPM
krb5-1.5-28.src.rpm SHA-256: 86fbccd1567abc2cb9e0e3c910391d6837618cb1a215028a631eb2b4a1b7572c
ppc
krb5-devel-1.5-28.ppc.rpm SHA-256: 51f9d2a5faf835fe7793160d4c887959656d9ae57304ee04eba5fd9b1f7c3385
krb5-devel-1.5-28.ppc64.rpm SHA-256: 2eeaf7afcc6e52b0403f24cb46cb456cd9d6cac3dd89019e531cdcf0056d2c02
krb5-libs-1.5-28.ppc.rpm SHA-256: 445e9ce2f7afb9214931b43ce11bc0757e88ae8485743e0048a80740addd1d73
krb5-libs-1.5-28.ppc64.rpm SHA-256: 2303527d84d6fbf4439701d5e3fcdbf559838d7c44a3ad2f3cb9e96511d96a6c
krb5-server-1.5-28.ppc.rpm SHA-256: 7b740319d47c748bd19279c2495bec4bfaefeffe2849f8efa4e472a857a2893c
krb5-workstation-1.5-28.ppc.rpm SHA-256: 1ba0a2911d6c1651fbcc5d040db37cdd224c441e1c2ddf8caeb0f85dfd93b9ce

Red Hat Enterprise Linux Server from RHUI 5

SRPM
krb5-1.5-28.src.rpm SHA-256: 86fbccd1567abc2cb9e0e3c910391d6837618cb1a215028a631eb2b4a1b7572c
x86_64
krb5-devel-1.5-28.i386.rpm SHA-256: 5e6c38319f20e6fb8c4fc0f4dc38fca98af9c90c834506f12c51136fb73c2235
krb5-devel-1.5-28.x86_64.rpm SHA-256: 11aab738d496e60398c5497095ab17a3c30f8392557acd2ad551560b96acca9b
krb5-libs-1.5-28.i386.rpm SHA-256: 0d38f85c66c224d1b1c764457c9ce3e216bcfa992ba5e7b9ca8256e99d4491fd
krb5-libs-1.5-28.x86_64.rpm SHA-256: 723083d535f0dd795e9cf049e59b5c466e34403c0844895e9d805fe02ab78359
krb5-server-1.5-28.x86_64.rpm SHA-256: 479e40dcb2bfc7f627f4d6de84f2209f7e3f5b8be087328938f251553f89e4f4
krb5-workstation-1.5-28.x86_64.rpm SHA-256: dcca945c41a8d0aa02209d1f717de1024abf1228371d03cc43a51b05de420fd6
i386
krb5-devel-1.5-28.i386.rpm SHA-256: 5e6c38319f20e6fb8c4fc0f4dc38fca98af9c90c834506f12c51136fb73c2235
krb5-libs-1.5-28.i386.rpm SHA-256: 0d38f85c66c224d1b1c764457c9ce3e216bcfa992ba5e7b9ca8256e99d4491fd
krb5-server-1.5-28.i386.rpm SHA-256: 322272fbf0625b8db7ef2c61768f726c512709daa91dd8c0ba295c498a0a1c9f
krb5-workstation-1.5-28.i386.rpm SHA-256: 324917b73734f02a121b9faa2de27dc1632c5adad138cd78d94f4d151875a1f5

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility