CVE-2011-4151: Input Validation
Published Oct 20, 2011
·Updated
The krb5db2lockoutaudit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley DB) back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, a different vulnerability than CVE-2011-1528.
Affected Software
5 affected components
MIT Kerberos 5=1.8
MIT Kerberos 5=1.8.1
MIT Kerberos 5=1.8.2
MIT Kerberos 5=1.8.3
MIT Kerberos 5=1.8.4
Event History
Oct 20, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4151?
CVE-2011-4151 is classified as a denial of service vulnerability.
2
How do I fix CVE-2011-4151?
To mitigate CVE-2011-4151, upgrade MIT Kerberos 5 to version 1.8.5 or later.
3
Who is affected by CVE-2011-4151?
CVE-2011-4151 affects users of MIT Kerberos 5 versions 1.8 through 1.8.4 using the db2 backend.
4
What types of attacks can exploit CVE-2011-4151?
Attackers can exploit CVE-2011-4151 to cause a denial of service via unspecified vectors.
5
When was CVE-2011-4151 disclosed?
CVE-2011-4151 was disclosed on December 7, 2011.