PT-2009-6745 · Mit+1 · Mit-Krb5+2

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2009-0844

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions krb5 versions 1.5 through 1.6.3 mit-krb5 versions prior to 1.6.3-r6
Description The issue affects the confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. The get input token function in the SPNEGO implementation allows remote attackers to cause a denial of service and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read.
Recommendations For krb5 versions 1.5 through 1.6.3, update to a version later than 1.6.3 to resolve the issue. For mit-krb5 versions prior to 1.6.3-r6, update to version 1.6.3-r6 or later to resolve the issue. As a temporary workaround, consider restricting access to the SPNEGO implementation until a patch is available.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04525
BDU:2015-04526
BDU:2015-04527
BDU:2015-04528
BDU:2015-04529
BDU:2015-09389
CVE-2009-0844
DSA-1766-1
OPENSUSE-SU-2024:10004-1
RHSA-2009:0408
RHSA-2009_0408

Produtos afetados

Red Hat
Krb5
Mit-Krb5