Patches & Updates
Deploy and monitor updates to all of your systems through Sun from anywhere you have an Internet connection.
Start today with Knowledge-based software update services for Solaris and Linux.
Patches:
Download Patch (645304 bytes): HTTP 
Download Signed Patch (647485 bytes): HTTP 
Signed Patch Documentation  Patch Finder

Obsoleted by: 115168-06 SunOS 5.9_x86: usr/lib/security/pam_krb5.so.1 Patch


Disclaimer: 

Please note: Although OBSOLETED patches are available on SunSolve, Sun recommends using the most recent patches and the most recent revision of those patches. OBSOLETED patches do not include the latest bug fixes and/or product enhancements, and may require the installation of additional patches as a corrective measure.

Status: OBSOLETE
Patch Id: 115168-05
Summary: Obsoleted by: 115168-06 SunOS 5.9_x86: usr/lib/security/pam_krb5.so.1 Patch
Date:  Aug/31/2004


******************************************************
   The items made available through this website
   are subject to United States export laws and
   may be subject to export and import laws
   of other countries. You agree to strictly comply
   with all such laws and obtain licenses to
   export, re-export, or import as may be required.
   Unless expressly authorized by the United States
   Government to do so you will not, directly or
   indirectly, export or re-export the items made
   available through this website, nor direct the
   items therefrom, to any  embargoed or restricted
   country identified in the United States export
   laws, including but not limited to the Export
   Administration Regulations (15 C.F.R. Parts
   730-774).
******************************************************
Installation Requirements:
Reboot immediately after patch is installed                      
                      Install in Single User Mode
Solaris Release: 9_x86
Sun OS Release: 5.9_x86
Unbundled Product: 
Unbundled Release: 
Xref: This patch available for SPARC as patch 112908
Topic: 
SunOS 5.9_x86: usr/lib/security/pam_krb5.so.1 Patch
Relevant Architecture: i386
BugId's fixed with this patch:

4430138 4516537 4526202 4630574 4711993 4727224 4743181 4744280 4794436 4807010 4830044 4836676 4837278 4841013 4846024 4847827 4865664 4881066 4882946 4995543 5004688 5055875 5063407

Changes incorporated in this version:

4807010 4837278 4865664 5055875 5063407

Patches accumulated and obsoleted by this patch:

113990-05

Patches which conflict with this patch: 

Required Patches:

Obsoleted by:
 
Files Included in this Patch: 
/kernel/misc/kgss/do_kmech_krb5
/kernel/misc/kgss/gl_kmech_krb5
/usr/lib/gss/gl/abi/abi_mech_krb5.so.1
/usr/lib/gss/gl/mech_krb5.so.1
/usr/lib/security/pam_krb5.so.1
/usr/lib/security/pam_krb5_migrate.so
/usr/lib/security/pam_krb5_migrate.so.1
Problem Description: 
4807010 Crash in the gssapi module
4837278 Kerberos utilities should include automigrate capability
5055875 buffer overflow in (undocumented) auth_to_local rules
4865664 gssapi/krb5 may hang with corrupted data
5063407 memory corruption between decode_krb5_ap_req() and krb5_gss_accept_sec_context()
 
(from 115168-04)
 
4995543 pam_krb5.so.1 from 112908-12 causes SEGV when using *su* or dtsession lock
5004688 Kerberos patch 112908-12 causes user passwords to be logged in clear text
 
(from 115168-03)
 
4794436 strict TGT verification in pam_krb5 should be configurable
4430138 pam_krb5 has wrong return codes for some service module function
4516537 pam_krb5 does not conform to the PAM standards set forth in pam(3PAM)
4711993 mech_krb5:  memory caching MUST be enabled in kerberos mech
4841013 krb5 memory cache code should use mktemp instead of mkstemp
4846024 krb5 err msg: login: /tmp/krb5cc_35224 owned by 35224 instead of 0
4881066 pam_krb5 setcred function causes BUS error due to incorrectly freed memory
 
(from 115168-02)
 
4836676 Bounds checks not in place for princs in krbv5
 
(from 115168-01)
 
4830044 pam_krb5 needs to be repository aware
 
(from 113990-05)
 
4882946 GSS_C_NO_BUFFER: gss_init_sec_context gives an Error code
 
(from 113990-04)
 
4836676 Bounds checks not in place for princs in krbv5
 
(from 113990-03)
 
4847827 Kerberos patch 112908-07 Error verifying TGT with host, Bad encryption type
 
(from 113990-02)
 
4630574 pam_krb5 should not reimplement utility functions and use libpam utilities
4743181 gss/kerberos frees a buffer returned to caller
 
(from 113990-01)
 
4526202 pam_krb5 auth can fail with multiple ftp sessions of same user
4727224 user application hangs at rpc_gss_seccreate()
4744280 gss_display_status() always returning error
Revision History: 

115168-04 115168-02 113990-05 115168-01 115168-03

Patch Installation Instructions: 
--------------------------------
 
For Solaris 2.0-2.6 releases, refer to the Install.info file and/or
the README within the patch for instructions on using the generic
'installpatch' and 'backoutpatch' scripts provided with each patch.
 
For Solaris 7-9 releases, refer to the man pages for instructions
on using 'patchadd' and 'patchrm' scripts provided with Solaris.
Any other special or non-generic installation instructions should be
described below as special instructions.  The following example
installs a patch to a standalone machine:
 
       example# patchadd /var/spool/patch/104945-02
 
The following example removes a patch from a standalone system:
 
       example# patchrm 104945-02
 
For additional examples please see the appropriate man pages.
Special Install Instructions: 
-----------------------------
 
Not all patches listed in this section as needed for the completion
of a fix or feature, may be available at the same time as this patch.
This allows the remaining fixes/features to be made available sooner.

NOTE 1: To get the complete fix of bug 4836676 "Bounds checks not
        in place for princs in krbv5" please install the following patches:
 
        116044-01 (or newer) kdb5_util
        116045-01 (or newer) krb5kdc
        116046-02 (or newer) libkadm5srv.so.1
        This patch now contains 113990-04 (or newer) mech_krb5.so.1 gl_kmech_krb5
        115168-03 (or newer) pam_krb5.so.1 (This patch)

NOTE 2: To get the complete fix for bugID 4837278, please also install
        the following patches (or newer):

        116044-02 kdb5_util
        116046-04 libkadm5srv.so.1

README -- Last modified date:  Monday, March 7, 2005

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 115168-05
Article Type : Patch Descriptions
Last reviewed : 2004-10-01
Audience : PUBLIC
Keywords : security encryption international pam_krb5 krbv5 pam_krb5 kerberos
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article
 
Contact About Sun News & Events Employment Site Map Privacy Terms of Use Trademarks Copyright Sun Microsystems, Inc. | SunSolve Version 7.4.0 #1