krb5: null pointer dereference in GSS-API library leads to DoS (MITKRB5-SA-2010-005)
Published May 19, 2010
6.8
MEDIUMCVSS 2.0
EPSS 6.88%
Description
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.
Affected products
No data.
Configuration 1
- ≤ 1.7.1
- ≥ 1.8 · < 1.8.2
Configuration 2
- 5.0
- 6.0
Configuration 3
- 6.06
- 8.04
- 9.04
- 9.10
- 10.04
Configuration 4
- n/a
Configuration 5
- 11.0
- 11.1
- 11.2
- 11.3
- 10
- 11
- 11
Configuration 6
- 11
- 12
- 13
No data.
Extras for RHEL 4
java-1.4.2-ibm-0:1.4.2.13.7-1jpp.3.el4
Fixed · RHSA-2010:0935
Extras for RHEL 4
java-1.4.2-ibm-0:1.4.2.13.8-1jpp.3.el4
Fixed · RHSA-2011:0152
Extras for RHEL 4
java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el4
Fixed · RHSA-2010:0807
Extras for RHEL 4
java-1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el4
Fixed · RHSA-2010:0987
Extras for RHEL 4
java-1.6.0-sun-1:1.6.0.22-1jpp.1.el4
Fixed · RHSA-2010:0770
Red Hat Enterprise Linux 3
krb5-0:1.2.7-72
Fixed · RHSA-2010:0423
Red Hat Enterprise Linux 4
krb5-0:1.3.4-62.el4_8.2
Fixed · RHSA-2010:0423
Red Hat Enterprise Linux 5
krb5-0:1.6.1-36.el5_5.4
Fixed · RHSA-2010:0423
Red Hat Enterprise Linux 6 Supplementary
java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el6
Fixed · RHSA-2010:0873
Red Hat Enterprise Linux 6 Supplementary
java-1.6.0-ibm-1:1.6.0.9.0-1jpp.4.el6
Fixed · RHSA-2010:0987
Red Hat Network Satellite Server v 5.4
java-1.6.0-ibm-1:1.6.0.9.1-1jpp.1.el5
Fixed · RHSA-2011:0880
Supplementary for Red Hat Enterprise Linux 5
java-1.4.2-ibm-0:1.4.2.13.7-1jpp.3.el5
Fixed · RHSA-2010:0935
Supplementary for Red Hat Enterprise Linux 5
java-1.4.2-ibm-0:1.4.2.13.8-1jpp.2.el5
Fixed · RHSA-2011:0152
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el5
Fixed · RHSA-2010:0807
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el5
Fixed · RHSA-2010:0987
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.22-1jpp.1.el5
Fixed · RHSA-2010:0770
Red Hat Enterprise Linux 6
krb5
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 4 | java-1.4.2-ibm-0:1.4.2.13.7-1jpp.3.el4 | Fixed | RHSA-2010:0935 |
| Extras for RHEL 4 | java-1.4.2-ibm-0:1.4.2.13.8-1jpp.3.el4 | Fixed | RHSA-2011:0152 |
| Extras for RHEL 4 | java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el4 | Fixed | RHSA-2010:0807 |
| Extras for RHEL 4 | java-1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el4 | Fixed | RHSA-2010:0987 |
| Extras for RHEL 4 | java-1.6.0-sun-1:1.6.0.22-1jpp.1.el4 | Fixed | RHSA-2010:0770 |
| Red Hat Enterprise Linux 3 | krb5-0:1.2.7-72 | Fixed | RHSA-2010:0423 |
| Red Hat Enterprise Linux 4 | krb5-0:1.3.4-62.el4_8.2 | Fixed | RHSA-2010:0423 |
| Red Hat Enterprise Linux 5 | krb5-0:1.6.1-36.el5_5.4 | Fixed | RHSA-2010:0423 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el6 | Fixed | RHSA-2010:0873 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.6.0-ibm-1:1.6.0.9.0-1jpp.4.el6 | Fixed | RHSA-2010:0987 |
| Red Hat Network Satellite Server v 5.4 | java-1.6.0-ibm-1:1.6.0.9.1-1jpp.1.el5 | Fixed | RHSA-2011:0880 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.4.2-ibm-0:1.4.2.13.7-1jpp.3.el5 | Fixed | RHSA-2010:0935 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.4.2-ibm-0:1.4.2.13.8-1jpp.2.el5 | Fixed | RHSA-2011:0152 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el5 | Fixed | RHSA-2010:0807 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el5 | Fixed | RHSA-2010:0987 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.22-1jpp.1.el5 | Fixed | RHSA-2010:0770 |
| Red Hat Enterprise Linux 6 | krb5 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (63)
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02257427 vendor-advisoryx_refsource_HPBroken Link
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041615.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041645.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041654.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00002.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=134254866602253&w=2 vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory
- http://osvdb.org/64744 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/39762 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/39784 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/39799 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/39818 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/39849 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/40346 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/40685 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/41967 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/42432 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/42974 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/43335 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/44954 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://support.avaya.com/css/P8/documents/100114315 x_refsource_CONFIRMThird Party Advisory
- http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-005.txt x_refsource_CONFIRMPatchVendor Advisory
- http://www.debian.org/security/2010/dsa-2052 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:100 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html x_refsource_CONFIRMThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0423.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0770.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0807.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0873.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0935.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0987.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0152.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0880.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/archive/1/511331/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/516397/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/40235 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-940-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-940-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA10-287A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA11-201A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html x_refsource_CONFIRMThird Party Advisory
- http://www.vupen.com/english/advisories/2010/1177 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2010/1192 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2010/1193 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2010/1196 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2010/1222 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2010/1574 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2010/1882 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2010/3112 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2011/0134 vdb-entryx_refsource_VUPENThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2010-1321 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=582466 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-1321
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11604 vdb-entrysignaturex_refsource_OVALBroken LinkThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7198 vdb-entrysignaturex_refsource_OVALBroken LinkThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7450 vdb-entrysignaturex_refsource_OVALBroken LinkThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2010-1321
Change history (0)
No recorded changes yet.