7.8
CVSSv2

CVE-2011-1527

Published: 20/10/2011 Updated: 21/01/2020
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The kdb_ldap plugin in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 up to and including 1.9.1, when the LDAP back end is used, allows remote malicious users to cause a denial of service (NULL pointer dereference and daemon crash) via a kinit operation with incorrect string case for the realm, related to the is_principal_in_realm, krb5_set_error_message, krb5_ldap_get_principal, and process_as_req functions.

Vulnerable Product Search on Vulmon Subscribe to Product

mit kerberos 5 1.9.1

mit kerberos 5 1.9

Vendor Advisories

Several denial of service issues were fixed in the Kerberos Key Distribution Center (KDC) ...
Multiple NULL pointer dereference and assertion failure flaws were found in the MIT Kerberos KDC when it was configured to use an LDAP (Lightweight Directory Access Protocol) or Berkeley Database (Berkeley DB) back end A remote attacker could use these flaws to crash the KDC (CVE-2011-1527, CVE-2011-1528, CVE-2011-1529) ...