PT-2011-1162 · Mit+1 · Mit-Krb5+2

Published

2011-02-08

·

Updated

2024-06-15

·

CVE-2011-0282

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions 1.6.x through 1.9 mit-krb5 versions prior to 1.9.2-r1
Description The issue allows remote attackers to cause a denial of service, potentially leading to a daemon crash, via a crafted principal name when an LDAP backend is used in MIT Kerberos 5. This can result in disruption of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations For MIT Kerberos 5 versions 1.6.x through 1.9, consider updating to a version later than 1.9 to resolve the issue. For mit-krb5 versions prior to 1.9.2-r1, update to version 1.9.2-r1 or later to fix the problem. As a temporary workaround, consider restricting access to the LDAP backend to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09426
CVE-2011-0282
OPENSUSE-SU-2024:10004-1
RHSA-2011:0199
RHSA-2011:0200
RHSA-2011_0199
RHSA-2011_0200

Affected Products

Mit Kerberos 5
Red Hat
Mit-Krb5