Lucene search

K
prionPRIOn knowledge basePRION:CVE-2010-1321
HistoryMay 19, 2010 - 6:30 p.m.

Null pointer dereference

2010-05-1918:30:00
PRIOn knowledge base
www.prio-n.com
5

6.7 Medium

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.7%

The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticatorโ€™s checksum field is missing.

References