PT-2010-2381 · Mit · Mit Kerberos 5
Jan Lieskovsky
·
Published
2010-03-25
·
Updated
2024-06-15
·
CVE-2010-0628
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
MIT Kerberos 5 versions 1.7 through 1.7.1
MIT Kerberos 5 versions 1.8 through 1.8.0
Description
The issue allows remote attackers to cause a denial of service, resulting in an assertion failure and daemon crash. This is achieved by sending an invalid packet that triggers incorrect preparation of an error token.
Recommendations
For MIT Kerberos 5 versions 1.7 through 1.7.1, update to version 1.7.2 or later.
For MIT Kerberos 5 versions 1.8 through 1.8.0, update to version 1.8.1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mit Kerberos 5