MIT Kerberos KDC TGS Handling NULL Pointer Dereference Denial Of Service Vulnerability
BID:50929
Info
MIT Kerberos KDC TGS Handling NULL Pointer Dereference Denial Of Service Vulnerability
| Bugtraq ID: | 50929 |
| Class: | Design Error |
| CVE: |
CVE-2011-1530 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2011 12:00AM |
| Updated: | Apr 13 2015 09:34PM |
| Credit: | Simo Sorce |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 MIT Kerberos 5 5.0 -1.4.1 MIT Kerberos 5 5.0 -1.4 MIT Kerberos 5 5.0 -1.3.6 MIT Kerberos 5 5.0 -1.3.5 MIT Kerberos 5 5.0 -1.3.4 MIT Kerberos 5 5.0 -1.3.3 MIT Kerberos 5 5.0 -1.2beta2 MIT Kerberos 5 5.0 -1.2beta1 MIT Kerberos 5 5.0 -1.1.1 MIT Kerberos 5 5.0 -1.1 MIT Kerberos 5 5.0 -1.0.x MIT Kerberos 5 1.8.1 MIT Kerberos 5 1.7.2 MIT Kerberos 5 1.6.2 MIT Kerberos 5 1.6.1 MIT Kerberos 5 1.6 MIT Kerberos 5 1.5.5 MIT Kerberos 5 1.5.4 MIT Kerberos 5 1.5.3 MIT Kerberos 5 1.5.2 MIT Kerberos 5 1.5.1 MIT Kerberos 5 1.5 MIT Kerberos 5 1.4.3 MIT Kerberos 5 1.4.2 MIT Kerberos 5 1.4.1 MIT Kerberos 5 1.4 MIT Kerberos 5 1.3.6 MIT Kerberos 5 1.3.5 MIT Kerberos 5 1.3.4 MIT Kerberos 5 1.3.3 MIT Kerberos 5 1.3.2 MIT Kerberos 5 1.3.1 MIT Kerberos 5 1.3 -alpha1 MIT Kerberos 5 1.3 MIT Kerberos 5 1.2.8 MIT Kerberos 5 1.2.7 MIT Kerberos 5 1.2.6 MIT Kerberos 5 1.2.5 MIT Kerberos 5 1.2.4 MIT Kerberos 5 1.2.3 MIT Kerberos 5 1.2.2 -beta1 MIT Kerberos 5 1.2.2 MIT Kerberos 5 1.2.1 MIT Kerberos 5 5-1.9 MIT Kerberos 5 1.8 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Gentoo Linux Avaya Aura Experience Portal 6.0 |
| Not Vulnerable: | |
Discussion
MIT Kerberos KDC TGS Handling NULL Pointer Dereference Denial Of Service Vulnerability
MIT Kerberos is prone to a remote denial-of-service vulnerability caused by a NULL-pointer dereference in KDC.
An attacker may exploit this issue to crash the affected service, resulting in denial-of-service conditions. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
MIT Kerberos is prone to a remote denial-of-service vulnerability caused by a NULL-pointer dereference in KDC.
An attacker may exploit this issue to crash the affected service, resulting in denial-of-service conditions. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Exploit / POC
MIT Kerberos KDC TGS Handling NULL Pointer Dereference Denial Of Service Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
MIT Kerberos KDC TGS Handling NULL Pointer Dereference Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2011 x86_64
Mandriva Linux Mandrake 2011
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva krb5-1.9.1-1.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-pkinit-openssl-1.9.1-1.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-server-1.9.1-1.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-server-ldap-1.9.1-1.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-workstation-1.9.1-1.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64krb53-1.9.1-1.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64krb53-devel-1.9.1-1.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva krb5-1.9.1-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-pkinit-openssl-1.9.1-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-server-1.9.1-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-server-ldap-1.9.1-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-workstation-1.9.1-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libkrb53-1.9.1-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libkrb53-devel-1.9.1-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
References
MIT Kerberos KDC TGS Handling NULL Pointer Dereference Denial Of Service Vulnerability
References:
References: