Back

MEDIUM

krb5: KDC hang when using LDAP backend caused by special principal name (MITKRB5-SA-2011-002)

Published Feb 10, 2011

Description

The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (file descriptor exhaustion and daemon hang) via a principal name that triggers use of a backslash escape sequence, as demonstrated by a \n sequence.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of krb5 as shipped with Red Hat Enterprise Linux 3 or 4 as they did not include support for the LDAP backend.

Metrics

Weaknesses (1)

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 10, 2011
Updated Aug 6, 2024
Reserved Jan 3, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Feb 8, 2011