Severity
10.0CRITICALNVD
EPSS
50.0%
top 2.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 2

Description

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages6 packages

Debianmit/krb5< 1.6.dfsg.4~beta1-13+3
NVDmit/kerberos_5< 1.6.4
NVDapple/mac_os_x< 10.5.7
NVDredhat/enterprise_linux_server2.0, 3.0, 4.0+2

Also affects: Fedora 10, 9, Ubuntu Linux 6.06, 7.10, 8.04, 8.10, Enterprise Linux 4.0, 4.7

Patches

🔴Vulnerability Details

3
GHSA
GHSA-777p-gw55-q56c: The asn1_decode_generaltime function in lib/krb5/asn2022-05-02
OSV
CVE-2009-0846: The asn1_decode_generaltime function in lib/krb5/asn2009-04-09
CVEList
CVE-2009-0846: The asn1_decode_generaltime function in lib/krb5/asn2009-04-09

📋Vendor Advisories

3
Ubuntu
Kerberos vulnerabilities2009-04-07
Red Hat
krb5: ASN.1 decoder can free uninitialized pointer when decoding an invalid encoding (MITKRB5-SA-2009-002)2009-04-07
Debian
CVE-2009-0846: krb5 - The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN....2009

💬Community

2
Bugzilla
CVE-2009-0846 krb5: ASN.1 decoder can free uninitialized pointer when decoding an invalid encoding (MITKRB5-SA-2009-002)2009-03-19
Bugzilla
CVE-2009-0844 krb5: buffer over-read in SPNEGO GSS-API mechanism (MITKRB5-SA-2009-001)2009-03-19
CVE-2009-0846 — Access of Uninitialized Pointer | cvebase