- EPSS 10.47%
- Published 10.02.2011 18:00:55
- Last modified 11.04.2025 00:51:21
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer dereference or buffer over-read, and daemon crash) via a crafted princi...
- EPSS 1.21%
- Published 10.02.2011 18:00:55
- Last modified 11.04.2025 00:51:21
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request packet that does not trigger a response packet.
- EPSS 8.65%
- Published 10.02.2011 18:00:18
- Last modified 11.04.2025 00:51:21
The do_standalone function in the MIT krb5 KDC database propagation daemon (kpropd) in Kerberos 1.7, 1.8, and 1.9, when running in standalone mode, does not properly handle when a worker child process "exits abnormally," which allows remote attackers...
CVE-2010-4020
- EPSS 0.49%
- Published 02.12.2010 16:22:21
- Last modified 11.04.2025 00:51:21
MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (1) AD-SIGNEDPATH or (2) AD-KDC-ISSUED signature, and possibly gain privileges, by leveraging the smal...
CVE-2010-4021
- EPSS 0.47%
- Published 02.12.2010 16:22:21
- Last modified 11.04.2025 00:51:21
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request, ak...
CVE-2010-1323
- EPSS 2.74%
- Published 02.12.2010 16:22:20
- Last modified 11.04.2025 00:51:21
MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distrib...
CVE-2010-1324
- EPSS 3.67%
- Published 02.12.2010 16:22:20
- Last modified 11.04.2025 00:51:21
MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum,...
CVE-2010-1322
- EPSS 1.84%
- Published 07.10.2010 21:00:01
- Last modified 11.04.2025 00:51:21
The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of s...
CVE-2010-1321
- EPSS 2.2%
- Published 19.05.2010 18:30:03
- Last modified 11.04.2025 00:51:21
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allo...
- EPSS 14.12%
- Published 22.04.2010 14:30:01
- Last modified 11.04.2025 00:51:21
Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code ...