MIT Kerberos GSS-API Library Remote Denial of Service Vulnerability

Related Vulnerabilities: CVE-2010-1321   CVE-2010-3541   CVE-2010-3548   CVE-2010-3549   CVE-2010-3550   CVE-2010-3551   CVE-2010-3552   CVE-2010-3553   CVE-2010-3554   CVE-2010-3555   CVE-2010-3556   CVE-2010-3557   CVE-2010-3558   CVE-2010-3559   CVE-2010-3560   CVE-2010-3561   CVE-2010-3562   CVE-2010-3563   CVE-2010-3565   CVE-2010-3566   CVE-2010-3567   CVE-2010-3568   CVE-2010-3569   CVE-2010-3570   CVE-2010-3571   CVE-2010-3572   CVE-2010-3573   CVE-2010-3574  

MIT Kerberos contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is in the GSS-API acceptor component due to lack of pointer validation.  An authenticated, remote attacker could exploit the vulnerability by making a crafted request to the affected component.  This action could cause the component to crash, resulting in a DoS condition. MIT has confirmed this vulnerability and released updated software. The vulnerability can be exploited only by an authenticated attacker, which somewhat reduces the threat of an attack on affected systems. Cisco Network Admission Control Guest Server may be affected if Active Directory single sign-on is enabled.