First published: Tue Nov 05 2013(Updated: )
It was reported [1] that if a KDC serves multiple realms, certain requests could cause the setup_server_realm() funtion to dereference a null pointer, resulting in a crash of the KDC (Key Distribution Center). This can be triggered by an unauthenticated user. This has been correct in git [2]. [1] <a href="http://mailman.mit.edu/pipermail/krb5-bugs/2013-November/010206.html">http://mailman.mit.edu/pipermail/krb5-bugs/2013-November/010206.html</a> [2] <a href="https://github.com/krb5/krb5/commit/5d2d9a1abe46a2c1a8614d4672d08d9d30a5f8bf">https://github.com/krb5/krb5/commit/5d2d9a1abe46a2c1a8614d4672d08d9d30a5f8bf</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/krb5 | <1.10.7 | 1.10.7 |
MIT Kerberos 5 | <1.10.7 | |
Debian Debian Linux | =7.0 | |
openSUSE openSUSE | =11.4 | |
openSUSE openSUSE | =12.2 | |
openSUSE openSUSE | =12.3 | |
openSUSE openSUSE | =13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.