CVE Database
/

CVE-2010-1322

Back to search

CVE-2010-1322

Published: Oct 7, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of service (daemon crash), or possibly obtain sensitive information, spoof authorization, or execute arbitrary code, via a TGS request that triggers an uninitialized pointer dereference, as demonstrated by a request from a Windows Active Directory client.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDVSA-2010:202
vendor-advisory
x_refsource_MANDRIVA
43756
vdb-entry
x_refsource_BID
ADV-2010-2865
vdb-entry
x_refsource_VUPEN
RHSA-2010:0863
vendor-advisory
x_refsource_REDHAT
SUSE-SR:2010:019
vendor-advisory
x_refsource_SUSE
USN-999-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now