NetBSD
Versions of kerberos which have been integrated into released
versions of NetBSD and distributed as part of the optional,
not-for-export "secr" sets are vulnerable to some of the problems
cited in the advisory. Integration of the fixes is in progress and
will be announced in a NetBSD security advisory when complete.
University of Washington
[...] we don't distribute client or server binaries with MIT Kerberos
support.
We distribute source that allows building on UNIX and PC with MIT
Kerberos. A site which wants to use Kerberos must build our software
(e.g. Pine, imapd, ipop[23]d) locally in order to use MIT Kerberos.
I did not see anything in this alert that specifically indicates a
problem for [our] clients or servers. As with all other software
built with MIT Kerberos, it would be prudent for a site that uses our
software with MIT Kerberos to rebuild it with the patched version of
MIT Kerberos.
The CERT Coordination Center thanks Tom Yu and the MIT Kerberos
Team for notifying us about these problem and their help in developing
this advisory.
Jeff
Havrilla was the primary author of the CERT/CC portions of this
document.
This document is available from:
http://www.cert.org/advisories/CA-2000-11.html
CERT/CC Contact Information
Email: cert@cert.org
Phone: +1 412-268-7090 (24-hour hotline)
Fax: +1 412-268-6989
Postal address:
-
CERT Coordination Center
Software Engineering Institute
Carnegie Mellon University
Pittsburgh PA 15213-3890
U.S.A.
CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4)
Monday through Friday; they are on call for emergencies during other
hours, on U.S. holidays, and on weekends.
Using encryption
We strongly urge you to encrypt sensitive information sent by
email. Our public PGP key is available from
If you prefer to use DES, please call the CERT hotline for more
information.
Getting security information
CERT publications and other security information are available from
our web site
* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
NO WARRANTY
Any material furnished by Carnegie Mellon University and the
Software Engineering Institute is furnished on an "as is"
basis. Carnegie Mellon University makes no warranties of any kind,
either expressed or implied as to any matter including, but not
limited to, warranty of fitness for a particular purpose or
merchantability, exclusivity or results obtained from use of the
material. Carnegie Mellon University does not make any warranty of any
kind with respect to freedom from patent, trademark, or copyright
infringement.