- EPSS 10.47%
- Veröffentlicht 10.02.2011 18:00:55
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer dereference or buffer over-read, and daemon crash) via a crafted princi...
- EPSS 1.21%
- Veröffentlicht 10.02.2011 18:00:55
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request packet that does not trigger a response packet.
- EPSS 8.65%
- Veröffentlicht 10.02.2011 18:00:18
- Zuletzt bearbeitet 11.04.2025 00:51:21
The do_standalone function in the MIT krb5 KDC database propagation daemon (kpropd) in Kerberos 1.7, 1.8, and 1.9, when running in standalone mode, does not properly handle when a worker child process "exits abnormally," which allows remote attackers...
CVE-2010-4020
- EPSS 0.49%
- Veröffentlicht 02.12.2010 16:22:21
- Zuletzt bearbeitet 11.04.2025 00:51:21
MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (1) AD-SIGNEDPATH or (2) AD-KDC-ISSUED signature, and possibly gain privileges, by leveraging the smal...
CVE-2010-4021
- EPSS 0.47%
- Veröffentlicht 02.12.2010 16:22:21
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request, ak...
CVE-2010-1323
- EPSS 2.74%
- Veröffentlicht 02.12.2010 16:22:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distrib...
CVE-2010-1324
- EPSS 3.67%
- Veröffentlicht 02.12.2010 16:22:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum,...
CVE-2010-1322
- EPSS 1.84%
- Veröffentlicht 07.10.2010 21:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of s...
CVE-2010-1321
- EPSS 2.2%
- Veröffentlicht 19.05.2010 18:30:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allo...
- EPSS 14.12%
- Veröffentlicht 22.04.2010 14:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code ...