CVE-2010-1321
published 2010-05-19CVE-2010-1321: The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in…
medium6.8CVSS 3.1
AVNACLAuSCNINAC
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | heimdal | < heimdal 1.4.0~git20100605.dfsg.1-1 (bookworm) | heimdal 1.4.0~git20100605.dfsg.1-1 (bookworm) |
| debian | krb5 | < heimdal 1.4.0~git20100605.dfsg.1-1 (bookworm) | heimdal 1.4.0~git20100605.dfsg.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| heimdal_project | heimdal | >= 0 < 1.4.0~git20100605.dfsg.1-1 | 1.4.0~git20100605.dfsg.1-1 |
| heimdal_project | heimdal | >= 0 < 1.4.0~git20100605.dfsg.1-1 | 1.4.0~git20100605.dfsg.1-1 |
| heimdal_project | heimdal | >= 0 < 1.4.0~git20100605.dfsg.1-1 | 1.4.0~git20100605.dfsg.1-1 |
| heimdal_project | heimdal | >= 0 < 1.4.0~git20100605.dfsg.1-1 | 1.4.0~git20100605.dfsg.1-1 |
| mit | kerberos_5 | <= 1.7.1 | — |
| mit | kerberos_5 | >= 1.8 < 1.8.2 | 1.8.2 |
| mit | krb5 | >= 0 < 1.8.1+dfsg-3 | 1.8.1+dfsg-3 |
| mit | krb5 | >= 0 < 1.8.1+dfsg-3 | 1.8.1+dfsg-3 |
| mit | krb5 | >= 0 < 1.8.1+dfsg-3 | 1.8.1+dfsg-3 |
| mit | krb5 | >= 0 < 1.8.1+dfsg-3 | 1.8.1+dfsg-3 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvd6.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.8MEDIUM