PT-2009-6746 · Mit+1 · Mit-Krb5+2

Richard Evans

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-0845

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions krb5 versions 1.5 through 1.6.3 mit-krb5 versions prior to 1.6.3-r6
Description The issue concerns multiple vulnerabilities in the krb5 package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, the spnego gss accept sec context function in lib/gssapi/spnego/spnego mech.c in MIT Kerberos 5 allows remote attackers to cause a denial of service via invalid ContextFlags data in the reqFlags field in a negTokenInit token.
Recommendations For krb5 versions 1.5 through 1.6.3, update to a version later than 1.6.3 to resolve the issue. For mit-krb5 versions prior to 1.6.3-r6, update to version 1.6.3-r6 or later to resolve the issue. As a temporary workaround, consider restricting access to the spnego gss accept sec context function until a patch is available.

Exploit

Fix

DoS

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04525
BDU:2015-04526
BDU:2015-04527
BDU:2015-04528
BDU:2015-04529
BDU:2015-09389
CVE-2009-0845
DSA-1766-1
OPENSUSE-SU-2024:10004-1
RHSA-2009:0408
RHSA-2009_0408

Affected Products

Red Hat
Krb5
Mit-Krb5