PT-2009-6744 · Mit+2 · Krb5-Devel+11

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-0846

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions krb5 versions prior to 1.6.4 mit-krb5 versions prior to 1.6.3-r6 krb5-libs versions 1.3.4 krb5-devel versions 1.3.4 krb5-server versions 1.3.4 krb5-workstation versions 1.3.4 krb5-debuginfo versions (affected versions not specified) krb5-debuginfo-32bit versions (affected versions not specified) krb5-debuginfo-64bit versions (affected versions not specified) krb5-debugsource versions (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out remotely.
Recommendations For krb5 versions prior to 1.6.4, update to version 1.6.4 or later. For mit-krb5 versions prior to 1.6.3-r6, update to version 1.6.3-r6 or later. For krb5-libs versions 1.3.4, update to a version that is not affected by this issue. For krb5-devel versions 1.3.4, update to a version that is not affected by this issue. For krb5-server versions 1.3.4, update to a version that is not affected by this issue. For krb5-workstation versions 1.3.4, update to a version that is not affected by this issue. For krb5-debuginfo, krb5-debuginfo-32bit, krb5-debuginfo-64bit, and krb5-debugsource, update to versions that are not affected by this issue, as the specific affected versions are not specified.

Fix

DoS

Buffer Overflow

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04525
BDU:2015-04526
BDU:2015-04527
BDU:2015-04528
BDU:2015-04529
BDU:2015-07290
BDU:2015-07291
BDU:2015-07303
BDU:2015-07308
BDU:2015-07315
BDU:2015-07323
BDU:2015-08502
BDU:2015-08503
BDU:2015-08504
BDU:2015-08505
BDU:2015-08506
BDU:2015-08507
BDU:2015-09389
CVE-2009-0846
DSA-1766-1
HPSBUX02421
OPENSUSE-SU-2024:10004-1
RHSA-2009:0408
RHSA-2009:0409
RHSA-2009:0410
RHSA-2009_0408
RHSA-2009_0409

Affected Products

Hp-Ux
Red Hat
Krb5
Krb5-Debuginfo
Krb5-Debuginfo-32Bit
Krb5-Debuginfo-64Bit
Krb5-Debugsource
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation
Mit-Krb5