CVE-2008-0062
19.03.2008, 10:44
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.Enginsight
Vendor | Product | Version |
---|---|---|
mit | kerberos_5 | 𝑥 ≤ 1.6.3 |
debian | debian_linux | 3.1 |
debian | debian_linux | 4.0 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 6.10 |
canonical | ubuntu_linux | 7.04 |
canonical | ubuntu_linux | 7.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References