Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MIT Kerberos ASN.1 Decoder Heap Corruption Vulnerability

A vulnerability has been discovered in MIT Kerberos. It has been reported that, due to insufficient bounds checking and sanitization of user-supplied data, Kerberos is prone to memory corruption.

A remote attacker may trigger this condition my supplying a negative length value in a malicious packet sent to a target server. Successful exploitation of this issue may result in a denial of service.

As this issue affects older releases of Kerberos, a BID may already exist. If this is issue proves to be covered in a previous database entry, this BID will be retired and the correct BID will be updated accordingly.







 

Privacy Statement
Copyright 2008, SecurityFocus