Release date: 2011-12-06
Updated on:
Affected Systems:
MIT Kerberos 5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50929
Cve id: CVE-2011-1530
Kerberos is a widely used super-powerful encryption to verify the network protocol between the client and the server.
MIT Kerberos has a denial of service vulnerability caused by NULL pointer reference in the implementation of process_tgs_req function in do_tgs_req.c of KDC. Remote attackers can exploit this vulnerability to crash affected services.
<* Source: Simo Sorce
Link: http://www.securityfocus.com/archive/1/520756
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MIT
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://web.mit.edu/kerberos/www/advisories/index.html