|
MIT Kerberos ASN.1 Decoder Heap Corruption Vulnerability
A vulnerability has been discovered in MIT Kerberos. It has been reported that, due to insufficient bounds checking and sanitization of user-supplied data, Kerberos is prone to memory corruption. A remote attacker may trigger this condition my supplying a negative length value in a malicious packet sent to a target server. Successful exploitation of this issue may result in a denial of service. As this issue affects older releases of Kerberos, a BID may already exist. If this is issue proves to be covered in a previous database entry, this BID will be retired and the correct BID will be updated accordingly. |
|
|
Privacy Statement |