Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-0281

Опубликовано: 08 фев. 2011
Источник: redhat
CVSS2: 5

Описание

The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (file descriptor exhaustion and daemon hang) via a principal name that triggers use of a backslash escape sequence, as demonstrated by a \n sequence.

Отчет

This issue did not affect the versions of krb5 as shipped with Red Hat Enterprise Linux 3 or 4 as they did not include support for the LDAP backend.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3krb5Not affected
Red Hat Enterprise Linux 4krb5Not affected
Red Hat Enterprise Linux 5krb5FixedRHSA-2011:019908.02.2011
Red Hat Enterprise Linux 6krb5FixedRHSA-2011:020008.02.2011

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=668719krb5: KDC hang when using LDAP backend caused by special principal name (MITKRB5-SA-2011-002)

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (file descriptor exhaustion and daemon hang) via a principal name that triggers use of a backslash escape sequence, as demonstrated by a \n sequence.

nvd
больше 14 лет назад

The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (file descriptor exhaustion and daemon hang) via a principal name that triggers use of a backslash escape sequence, as demonstrated by a \n sequence.

debian
больше 14 лет назад

The unparse implementation in the Key Distribution Center (KDC) in MIT ...

github
около 3 лет назад

The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (file descriptor exhaustion and daemon hang) via a principal name that triggers use of a backslash escape sequence, as demonstrated by a \n sequence.

oracle-oval
больше 14 лет назад

ELSA-2011-0199: krb5 security update (IMPORTANT)

5 Medium

CVSS2