Kerberos is a network authentication system which allows clients andservers to authenticate to each other using symmetric encryption and atrusted third-party, the Key Distribution Center (KDC).An invalid free flaw was found in the password-changing capability of theMIT Kerberos administration daemon, kadmind. A remote, unauthenticatedattacker could use this flaw to cause kadmind to abort via aspecially-crafted request. (CVE-2011-0285)All krb5 users should upgrade to these updated packages, which contain abackported patch to correct this issue. After installing the updatedpackages, the kadmind daemon will be restarted automatically.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center