LWN.net Logo

krb5: denial of service

Package(s):krb5 CVE #(s):CVE-2010-0283
Created:February 19, 2010 Updated:March 24, 2010
Description: From the Red Hat bugzilla:

A flaw was found in how the KDC processed invalid requests. An unauthenticated remote attacker could send an invalid request to a KDC process that would cause it to crash due to an assertion failure, resulting in a denial of service of the KDC.

This flaw only affects MIT krb5 version 1.7 and later; earlier versions did not contain the vulnerable code.

Alerts:
Ubuntu USN-916-1 2010-03-23
SuSE SUSE-SR:2010:005 2010-02-23
Fedora FEDORA-2010-1722 2010-02-18
Gentoo 201201-13 2012-01-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds