[krbdev.mit.edu #7637] git commit

Tom Yu via RT rt-comment at krbdev.mit.edu
Wed May 15 14:46:22 EDT 2013


As far as I can tell, this bug dates back to the original
implementation of the kpasswd service in our code.

A possible simple mitigation is to block UDP packets destined for the
kpasswd service if they have a source port of 464 (possibly also 7
(echo), 19 (chargen), etc., or anything < 1024 if you're being
especially paranoid).



More information about the krb5-bugs mailing list