CVE Database
/

CVE-2011-1530

Back to search

CVE-2011-1530

Published: Dec 8, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS request that triggers an error other than the KRB5_KDB_NOENTRY error.

VendorProductVersions

n/a

n/a

affected
n/a

References

47124
third-party-advisory
x_refsource_SECUNIA
kerberos-processtgsreq-dos(71655)
vdb-entry
x_refsource_XF
50929
vdb-entry
x_refsource_BID
RHSA-2011:1790
vendor-advisory
x_refsource_REDHAT
MDVSA-2011:184
vendor-advisory
x_refsource_MANDRIVA
1026374
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now