FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-0282

This CVE name corresponds to:

Entered Topic
2011-04-14 krb5 -- MITKRB5-SA-2011-002, KDC vulnerable to hang when using LDAP back end

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-0282
Phase Assigned(20110103)

Description

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer dereference or buffer over-read, and daemon crash) via a crafted principal name.

References

Source Reference
BUGTRAQ 20110208 MITKRB5-SA-2011-002 KDC denial of service attacks [CVE-2011-0281 CVE-2011-0282 CVE-2011-0283]
BUGTRAQ 20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console
CONFIRM http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-002.txt
CONFIRM http://www.vmware.com/security/advisories/VMSA-2011-0012.html
MANDRIVA MDVSA-2011:024
MANDRIVA MDVSA-2011:025
REDHAT RHSA-2011:0199
REDHAT RHSA-2011:0200
SUSE SUSE-SR:2011:004
BID 46271
SECTRACK 1025037
SECUNIA 43260
SECUNIA 43273
SECUNIA 43275
SECUNIA 46397
SREASON 8073
VUPEN ADV-2011-0330
VUPEN ADV-2011-0333
VUPEN ADV-2011-0347
VUPEN ADV-2011-0464
XF kerberos-ldap-dos(65323)