Why not remove some more of the panic and actually describe what is wrong.
Buffer overflow? Bad assumptions of environmental variables. Follows
links in /tmp? Etc. This would at least help other people look for
solutions (and/or bugs in other versions of kerberos). Your option to
include "exploitz" or not, but at least a description slightly more then
"kerberos is insecure".
: The bug is still a very serious one.
This list used to be "full-disclosure", or at least slightly.
-- -Matt (panzer@dhp.com) -- DataHaven Project - http://www.dhp.com/ "That which can never be enforced should not be prohibited."