CVE-2011-0281Allocation of File Descriptors or Handles Without Limits or Throttling in Kerberos

CWE-31015 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
10.8%
top 6.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10
Latest updateMay 13

Description

The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (file descriptor exhaustion and daemon hang) via a principal name that triggers use of a backslash escape sequence, as demonstrated by a \n sequence.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

Debianmit/krb5< 1.8.3+dfsg-5+3
NVDmit/kerberos5-1.6.3
NVDmit/kerberos_510 versions+9

🔴Vulnerability Details

3
GHSA
GHSA-pm35-jvrf-37g2: The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 12022-05-13
CVEList
CVE-2011-0281: The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 12011-02-10
OSV
CVE-2011-0281: The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 12011-02-10

📋Vendor Advisories

3
Ubuntu
Kerberos vulnerabilities2011-02-15
Red Hat
krb5: KDC hang when using LDAP backend caused by special principal name (MITKRB5-SA-2011-002)2011-02-08
Debian
CVE-2011-0281: krb5 - The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos ...2011

💬Community

8
Bugzilla
CVE-2010-4022 CVE-2011-0281 CVE-2011-0282 krb5 various flaws [fedora-all]2011-02-08
Bugzilla
CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)2011-02-08
Bugzilla
CVE-2010-4465 OpenJDK Swing timer-based security manager bypass (6907662)2011-02-08
Bugzilla
CVE-2010-4469 OpenJDK Hotspot verifier heap corruption (6878713)2011-02-08
Bugzilla
CVE-2010-4470 OpenJDK JAXP untrusted component state manipulation (6927050)2011-02-08
CVE-2011-0281 — MIT Kerberos vulnerability | cvebase