|
|
| |
|
| |
krb5: code execution
| Package(s): | krb5 |
CVE #(s): | CVE-2012-1014
|
| Created: | August 1, 2012 |
Updated: | March 18, 2013 |
| Description: |
From the Debian advisory:
By sending specially crafted AS-REQ (Authentication Service Request) to a KDC
(Key Distribution Center), an attacker could make it free an uninitialized
pointer, corrupting the heap. This can lead to process crash or even arbitrary
code execution. |
| Alerts: |
|
( Log in to post comments)
|
|
|