PT-2010-5609 · Mit+2 · Mit-Krb5+3

Brian Almeida

+2

·

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2010-1321

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions prior to 1.8.2 mit-krb5 versions prior to 1.9.2-r1
Description The issue is related to multiple vulnerabilities in the MIT Kerberos 5 package, which can lead to a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing. The kg accept krb5 function in krb5/accept sec context.c does not properly check for invalid GSS-API tokens. The vulnerabilities can be exploited remotely.
Recommendations For MIT Kerberos 5 versions prior to 1.8.2, update to version 1.8.2 or later. For mit-krb5 versions prior to 1.9.2-r1, update to version 1.9.2-r1 or later. As a temporary workaround, consider disabling the kg accept krb5 function until a patch is available. Restrict access to the GSS-API library to minimize the risk of exploitation. Avoid using the AP-REQ message with missing authenticator's checksum field in the affected API endpoint until the issue is resolved.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00999
BDU:2015-01000
BDU:2015-01001
BDU:2015-01002
BDU:2015-01003
BDU:2015-01004
BDU:2015-01005
BDU:2015-01006
BDU:2015-01007
BDU:2015-01008
BDU:2015-01009
BDU:2015-01010
BDU:2015-01011
BDU:2015-01012
BDU:2015-09426
CVE-2010-1321
DSA-2052-1
HPSBUX02544
OPENSUSE-SU-2024:10004-1
RHSA-2010:0423
RHSA-2010:0770
RHSA-2010:0807
RHSA-2010:0873
RHSA-2010:0935
RHSA-2010:0987
RHSA-2010_0423
RHSA-2010_0873
RHSA-2010_0987
RHSA-2011:0152
RHSA-2011:0880

Produtos afetados

Java Platform
Mit Kerberos 5
Red Hat
Mit-Krb5