Solaris 10 Kerberos Denial of Service Vulnerability CVE-2010-0283 -- patch??
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0283
I can't find anything listed on sun's website. I'm not running Kerberos, but I have the kerberos packages installed. Since kerberos is a required core package -- I can't remove it.
Is there any official sun statement or stance on CVE-2010-0283? I need to get this mitigated immediately.
My security folks are breathing down my neck.
I know that since I'm not running Kerberos, I'm not vulnerable. But since the libkrb5.so files exist, I can't wiggle out of it in thier eyes.
Thanks!