krb5: multiple vulnerabilities
Package(s): | krb5 | CVE #(s): | CVE-2011-1527 CVE-2011-1528 CVE-2011-1529 | ||||||||||||||||||||||||||||||||||||||||
Created: | October 19, 2011 | Updated: | January 5, 2012 | ||||||||||||||||||||||||||||||||||||||||
Description: | From the Red Hat advisory:
Multiple NULL pointer dereference and assertion failure flaws were found in the MIT Kerberos KDC when it was configured to use an LDAP (Lightweight Directory Access Protocol) or Berkeley Database (Berkeley DB) back end. A remote attacker could use these flaws to crash the KDC. (CVE-2011-1527, CVE-2011-1528, CVE-2011-1529) Red Hat would like to thank the MIT Kerberos project for reporting the CVE-2011-1527 issue. Upstream acknowledges Andrej Ota as the original reporter of CVE-2011-1527. | ||||||||||||||||||||||||||||||||||||||||||
Alerts: |
|