5
CVSSv2

CVE-2006-5989

Published: 20/11/2006 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the der_get_oid function in mod_auth_kerb 5.0 allows remote malicious users to cause a denial of service (crash) via a crafted Kerberos message that triggers a heap-based buffer overflow in the component array.

Vulnerable Product Search on Vulmon Subscribe to Product

mod auth kerb mod auth kerb 5.0

Vendor Advisories

Debian Bug report logs - #400589 libapache-mod-auth-kerb: Remote Vulnerability (CVE-2006-5989) Package: libapache-mod-auth-kerb; Maintainer for libapache-mod-auth-kerb is Ghe Rivero <ghe@debianorg>; Reported by: Martin Schwier <schwier@uni-paderbornde> Date: Mon, 27 Nov 2006 14:03:06 UTC Severity: important Tags: c ...