PT-2008-1049 · Mit+1 · Mit Kerberos 5+1

Publicado

2008-03-18

·

Atualizado

2024-06-15

·

CVE-2008-0062

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions prior to the fixed version
Description The issue allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free. This is due to the KDC in MIT Kerberos 5 not setting a global variable for some krb4 message types. The vulnerability can be exploited remotely, potentially leading to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For MIT Kerberos 5 versions prior to the fixed version, update to the fixed version to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Initialization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06278
CVE-2008-0062
DSA-1524-1
OPENSUSE-SU-2024:10899-1
RHSA-2008:0164
RHSA-2008:0180
RHSA-2008:0181
RHSA-2008:0182
RHSA-2008_0164
RHSA-2008_0180

Produtos afetados

Mit Kerberos 5
Red Hat