Back

HIGH

krb5 KDC denial of service

Published Feb 21, 2010

Description

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of MIT Kerberos 5 as shipped with Red Hat Enterprise Linux 3, 4 or 5. Those versions do not contain the vulnerable code that was introduced in krb5 1.7.

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 21, 2010
Updated Aug 7, 2024
Reserved Jan 12, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Feb 16, 2010