5
CVSSv2

CVE-2009-3295

Published: 29/12/2009 Updated: 21/01/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 prior to 1.7.1 allows remote malicious users to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request.

Vulnerable Product Search on Vulmon Subscribe to Product

mit kerberos 5 1.7

Vendor Advisories

Jeff Blaine, Radoslav Bodo, Jakob Haufe, and Jorgen Wahlsten discovered that the Kerberos Key Distribution Center service did not correctly verify certain network traffic An unauthenticated remote attacker could send a specially crafted request that would cause the KDC to crash, leading to a denial of service ...