![](/assets/img/cve_300x82_sin_bg.png)
CVE-2012-1013 – krb5: kadmind denial of service
https://notcve.org/view.php?id=CVE-2012-1013
07 Jun 2012 — The check_1_6_dummy function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x, and 1.10.x before 1.10.2 allows remote authenticated administrators to cause a denial of service (NULL pointer dereference and daemon crash) via a KRB5_KDB_DISALLOW_ALL_TIX create request that lacks a password. La función check_1_6_dummy en lib/kadm5/srv/svr_principal.c en kadmind en MIT Kerberos 5 (también conocido como krb5) v1.8.x, v1.9.x y v1.10.x antes de v1.10.2 permite provocar una dene... • http://krbdev.mit.edu/rt/Ticket/Display.html?user=guest&pass=guest&id=7152 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2012-1012
https://notcve.org/view.php?id=CVE-2012-1012
07 Jun 2012 — server/server_stubs.c in the kadmin protocol implementation in MIT Kerberos 5 (aka krb5) 1.10 before 1.10.1 does not properly restrict access to (1) SET_STRING and (2) GET_STRINGS operations, which might allow remote authenticated administrators to modify or read string attributes by leveraging the global list privilege. server/server_stubs.c en la implementación del protocolo kadmin en MIT Kerberos 5 (también conocido como krb5) v1.10 antes de v1.10.1 no restringe debidamente el acceso a las operaciones (1... • http://krbdev.mit.edu/rt/Ticket/Display.html?user=guest&pass=guest&id=7093 • CWE-264: Permissions, Privileges, and Access Controls •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-1527 – krb5: KDC denial of service vulnerabilities (MITKRB5-SA-2011-006)
https://notcve.org/view.php?id=CVE-2011-1527
20 Oct 2011 — The kdb_ldap plugin in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.1, when the LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a kinit operation with incorrect string case for the realm, related to the is_principal_in_realm, krb5_set_error_message, krb5_ldap_get_principal, and process_as_req functions. El plug-in kdb_ldap en el centro de distribución de claves (KDC) en MIT Kerberos 5 (krb5) v1.9 a ... • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629558 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-4151
https://notcve.org/view.php?id=CVE-2011-4151
20 Oct 2011 — The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley DB) back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, a different vulnerability than CVE-2011-1528. La función krb5_db2_lockout_audit en el Centro de distribución de claves (KDC) en MIT Kerberos 5 (krb5) v1.8 a v1.8.4, cuando el DB2 (Berkeley DB) es usado, permite a atacantes remot... • http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-006.txt • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-1529 – krb5: KDC denial of service vulnerabilities (MITKRB5-SA-2011-006)
https://notcve.org/view.php?id=CVE-2011-1529
20 Oct 2011 — The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the db2 (aka Berkeley DB) or LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger certain process_as_req errors. La function lookup_lockout_policy function del centro de distribución de claves (“Key Distribution Center” o KDC) en MIT Kerberos 5 (krb5) 1.8 hasta la version ... • http://lists.opensuse.org/opensuse-security-announce/2011-10/msg00009.html • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-1528 – krb5: KDC denial of service vulnerabilities (MITKRB5-SA-2011-006)
https://notcve.org/view.php?id=CVE-2011-1528
20 Oct 2011 — The krb5_ldap_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the LDAP back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, related to the locked_check_p function. NOTE: the Berkeley DB vector is covered by CVE-2011-4151. La función krb5_ldap_lockout_audit en el Key Distribution Center (KDC) en MIT Kerberos 5 (también se conoce como krb5) versi... • http://lists.opensuse.org/opensuse-security-announce/2011-10/msg00009.html • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-0285 – MIT Kerberos 5 - kadmind Change Password Feature Remote Code Execution
https://notcve.org/view.php?id=CVE-2011-0285
15 Apr 2011 — The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition. La función process_chpw_request de schpw.c en la funcionalidad de cambio de contraseña de kadmind de MIT Kerberos 5 (krb5) 1.7 hasta la 1.9 libera un puntero inválido, lo que permite a ataca... • https://www.exploit-db.com/exploits/35606 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-0284 – (krb5kdc): Double-free flaw by handling error messages upon receiving certain AS_REQ's (MITKRB5-SA-2011-003)
https://notcve.org/view.php?id=CVE-2011-0284
20 Mar 2011 — Double free vulnerability in the prepare_error_as function in do_as_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 through 1.9, when the PKINIT feature is enabled, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an e_data field containing typed data. Doble Vulnerabilidad libre en la función prepare_error_as en do_as_req.c en el Key Distribution Center (KDC) en MIT Kerberos 5 (también conocido como krb5) v1.7 hasta v1.9, ... • http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056413.html • CWE-399: Resource Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-0282 – krb5: KDC crash when using LDAP backend caused by a special principal name (MITKRB5-SA-2011-002)
https://notcve.org/view.php?id=CVE-2011-0282
10 Feb 2011 — The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer dereference or buffer over-read, and daemon crash) via a crafted principal name. El Key Distribution Center (KDC) en MIT Kerberos 5 (también conocido como krb5) v1.6.x hasta v1.9 cuando un se utiliza un backend LDAP, permite a atacantes remotos provocar una denegación de servicio (desreferencia a puntero nulo o sobre-lectura, y caí... • http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00004.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-0283
https://notcve.org/view.php?id=CVE-2011-0283
10 Feb 2011 — The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request packet that does not trigger a response packet. El Key Distribution Center (KDC) en MIT Kerberos 5 (también conocido como krb5) v1.9, permite a atacantes remotos provocar una denegación de servicio (desreferencia a puntero nulo y caída de demonio) a través de un paquete de solicitud con formato incorrecto que no activa un ... • http://secunia.com/advisories/43260 •