Page 5 of 124 results (0.013 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

03 Mar 2013 — The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 attempts to find an agility KDF identifier in inappropriate circumstances, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted Draft 9 request. La función pkinit_server_return_padata en plugins/preauth/pkinit/pkinit_srv.c en la implementación PKINIT en el Ke... • http://krbdev.mit.edu/rt/Ticket/Display.html?id=7527 • CWE-476: NULL Pointer Dereference •

CVSS: 9.1EPSS: 1%CPEs: 3EXPL: 0

06 Aug 2012 — The process_as_req function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.10.x before 1.10.3 does not initialize a certain structure member, which allows remote attackers to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a malformed AS-REQ request. La función process_as_req en Key Distribution Center (KDC) en MIT Kerberos 5 (también conocido como krb5) v1.10.x anteriores a v1.10.3 no inicializa ciertos miembros de l... • http://lists.opensuse.org/opensuse-updates/2012-08/msg00016.html •

CVSS: 9.3EPSS: 3%CPEs: 11EXPL: 0

06 Aug 2012 — The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x before 1.10.3 attempts to calculate a checksum before verifying that the key type is appropriate for a checksum, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free, heap memory corruption, and daemon crash) via a crafted AS-REQ request. La función kdc_handle_protected_negotiation en Key Distribution... • http://lists.opensuse.org/opensuse-updates/2012-08/msg00016.html • CWE-20: Improper Input Validation •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0

07 Jun 2012 — server/server_stubs.c in the kadmin protocol implementation in MIT Kerberos 5 (aka krb5) 1.10 before 1.10.1 does not properly restrict access to (1) SET_STRING and (2) GET_STRINGS operations, which might allow remote authenticated administrators to modify or read string attributes by leveraging the global list privilege. server/server_stubs.c en la implementación del protocolo kadmin en MIT Kerberos 5 (también conocido como krb5) v1.10 antes de v1.10.1 no restringe debidamente el acceso a las operaciones (1... • http://krbdev.mit.edu/rt/Ticket/Display.html?user=guest&pass=guest&id=7093 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.5EPSS: 1%CPEs: 13EXPL: 1

07 Jun 2012 — The check_1_6_dummy function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x, and 1.10.x before 1.10.2 allows remote authenticated administrators to cause a denial of service (NULL pointer dereference and daemon crash) via a KRB5_KDB_DISALLOW_ALL_TIX create request that lacks a password. La función check_1_6_dummy en lib/kadm5/srv/svr_principal.c en kadmind en MIT Kerberos 5 (también conocido como krb5) v1.8.x, v1.9.x y v1.10.x antes de v1.10.2 permite provocar una dene... • http://krbdev.mit.edu/rt/Ticket/Display.html?user=guest&pass=guest&id=7152 •

CVSS: 7.8EPSS: 5%CPEs: 5EXPL: 0

20 Oct 2011 — The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley DB) back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, a different vulnerability than CVE-2011-1528. La función krb5_db2_lockout_audit en el Centro de distribución de claves (KDC) en MIT Kerberos 5 (krb5) v1.8 a v1.8.4, cuando el DB2 (Berkeley DB) es usado, permite a atacantes remot... • http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-006.txt • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 3%CPEs: 2EXPL: 0

20 Oct 2011 — The kdb_ldap plugin in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.1, when the LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a kinit operation with incorrect string case for the realm, related to the is_principal_in_realm, krb5_set_error_message, krb5_ldap_get_principal, and process_as_req functions. El plug-in kdb_ldap en el centro de distribución de claves (KDC) en MIT Kerberos 5 (krb5) v1.9 a ... • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629558 • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 3%CPEs: 7EXPL: 0

20 Oct 2011 — The krb5_ldap_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the LDAP back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, related to the locked_check_p function. NOTE: the Berkeley DB vector is covered by CVE-2011-4151. La función krb5_ldap_lockout_audit en el Key Distribution Center (KDC) en MIT Kerberos 5 (también se conoce como krb5) versi... • http://lists.opensuse.org/opensuse-security-announce/2011-10/msg00009.html • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 2%CPEs: 7EXPL: 0

20 Oct 2011 — The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the db2 (aka Berkeley DB) or LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger certain process_as_req errors. La function lookup_lockout_policy function del centro de distribución de claves (“Key Distribution Center” o KDC) en MIT Kerberos 5 (krb5) 1.8 hasta la version ... • http://lists.opensuse.org/opensuse-security-announce/2011-10/msg00009.html • CWE-20: Improper Input Validation •

CVSS: 10.0EPSS: 34%CPEs: 7EXPL: 1

15 Apr 2011 — The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition. La función process_chpw_request de schpw.c en la funcionalidad de cambio de contraseña de kadmind de MIT Kerberos 5 (krb5) 1.7 hasta la 1.9 libera un puntero inválido, lo que permite a ataca... • https://www.exploit-db.com/exploits/35606 • CWE-20: Improper Input Validation •