Back

MEDIUM

krb5: null pointer dereference in GSS-API library leads to DoS (MITKRB5-SA-2010-005)

Published May 19, 2010

Description

The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.

Affected products

Remediation

No remediation recorded yet.

References (63)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 19, 2010
Updated Aug 7, 2024
Reserved Apr 8, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date May 18, 2010