PT-2010-5609 · Mit+2 · Mit-Krb5+3

Brian Almeida

+2

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2010-1321

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions prior to 1.8.2 mit-krb5 versions prior to 1.9.2-r1
Description The issue is related to multiple vulnerabilities in the MIT Kerberos 5 package, which can lead to a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing. The kg accept krb5 function in krb5/accept sec context.c does not properly check for invalid GSS-API tokens. The vulnerabilities can be exploited remotely.
Recommendations For MIT Kerberos 5 versions prior to 1.8.2, update to version 1.8.2 or later. For mit-krb5 versions prior to 1.9.2-r1, update to version 1.9.2-r1 or later. As a temporary workaround, consider disabling the kg accept krb5 function until a patch is available. Restrict access to the GSS-API library to minimize the risk of exploitation. Avoid using the AP-REQ message with missing authenticator's checksum field in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00999
BDU:2015-01000
BDU:2015-01001
BDU:2015-01002
BDU:2015-01003
BDU:2015-01004
BDU:2015-01005
BDU:2015-01006
BDU:2015-01007
BDU:2015-01008
BDU:2015-01009
BDU:2015-01010
BDU:2015-01011
BDU:2015-01012
BDU:2015-09426
CVE-2010-1321
DSA-2052-1
HPSBUX02544
OPENSUSE-SU-2024:10004-1
RHSA-2010:0423
RHSA-2010:0770
RHSA-2010:0807
RHSA-2010:0873
RHSA-2010:0935
RHSA-2010:0987
RHSA-2010_0423
RHSA-2010_0873
RHSA-2010_0987
RHSA-2011:0152
RHSA-2011:0880

Affected Products

Java Platform
Mit Kerberos 5
Red Hat
Mit-Krb5