Back

MEDIUM

krb5: Assertion failure in GSSAPI SPNEGO mechanism (MITKRB5-SA-2010-002)

Published Mar 25, 2010

Description

The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in the SPNEGO GSS-API functionality in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2 and 1.8 before 1.8.1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid packet that triggers incorrect preparation of an error token.

Affected products

Remediation

Red Hat statement

Not vulnerable. This flaw does not affect MIT krb5 as provided in Red Hat Enterprise Linux 3, 4, and 5.

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 25, 2010
Updated Aug 7, 2024
Reserved Feb 12, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Mar 23, 2010