PT-2010-1096 · Mit+1 · Mit Kerberos 5+2
Sol Jerome
·
Published
2010-04-06
·
Updated
2024-02-02
·
CVE-2010-0629
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MIT Kerberos 5 versions 1.5 through 1.6.3
mit-krb5 versions prior to 1.9.2-r1
Description
The issue concerns multiple vulnerabilities in the mit-krb5 package that can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. A specific vulnerability involves a use-after-free issue in the
kadmin/server/server stubs.c file of kadmind, allowing remote authenticated users to cause a denial of service by sending an invalid API version number from a kadmin client.Recommendations
For MIT Kerberos 5 versions 1.5 through 1.6.3, update to a version later than 1.6.3 to resolve the issue.
For mit-krb5 versions prior to 1.9.2-r1, update to version 1.9.2-r1 or later to fix the vulnerabilities.
As a temporary workaround, consider restricting access to the
kadmind service until a patch is applied.Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mit Kerberos 5
Red Hat
Mit-Krb5