CVE-2009-0847
09.04.2009, 00:30
The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mit | kerberos | 5-1.6.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| krb5 |
| ||||||||||||||
| krb5-32bit |
| ||||||||||||||
| krb5-client |
| ||||||||||||||
| krb5-devel |
| ||||||||||||||
| krb5-doc |
| ||||||||||||||
| krb5-plugin-kdb-ldap |
| ||||||||||||||
| krb5-plugin-preauth-otp |
| ||||||||||||||
| krb5-plugin-preauth-pkinit |
| ||||||||||||||
| krb5-server |
|
Common Weakness Enumeration
References