LWN.net Logo

krb5: code execution

Package(s):krb5 CVE #(s):CVE-2012-1014
Created:August 1, 2012 Updated:March 18, 2013
Description: From the Debian advisory:

By sending specially crafted AS-REQ (Authentication Service Request) to a KDC (Key Distribution Center), an attacker could make it free an uninitialized pointer, corrupting the heap. This can lead to process crash or even arbitrary code execution.

Alerts:
Debian DSA-2518-1 2012-07-31
Ubuntu USN-1520-1 2012-07-31
Fedora FEDORA-2012-11388 2012-08-05
openSUSE openSUSE-SU-2012:0967-1 2012-08-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds