Back

HIGH

krb: KDC integer overflows in AES and RC4 decryption routines (MITKRB5-SA-2009-004)

Published Jan 13, 2010

Description

Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 13, 2010
Updated Aug 7, 2024
Reserved Dec 4, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Jan 12, 2010