CVE-2011-0283: Null Pointer Dereference
Published Feb 10, 2011
·Updated
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request packet that does not trigger a response packet.
Affected Software
1 affected component
MIT Kerberos 5=1.9
Event History
Feb 10, 2011
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0283?
CVE-2011-0283 has a severity rating that indicates it can lead to a denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2011-0283?
To fix CVE-2011-0283, upgrade your MIT Kerberos 5 installation to a version beyond 1.9 where the vulnerability is addressed.
3
Who is affected by CVE-2011-0283?
CVE-2011-0283 affects users of MIT Kerberos 5 version 1.9.
4
What kind of attack does CVE-2011-0283 enable?
CVE-2011-0283 allows remote attackers to crash the KDC through a malformed request packet.
5
What can be the impact of exploiting CVE-2011-0283?
Exploiting CVE-2011-0283 can lead to a denial of service condition, causing the KDC daemon to crash.