Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-0846

Опубликовано: 09 апр. 2009
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 10

Описание

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.

РелизСтатусПримечание
dapper

released

1.4.3-5ubuntu0.8
devel

released

1.6.dfsg.4~beta1-5ubuntu2
gutsy

released

1.6.dfsg.1-7ubuntu0.2
hardy

released

1.6.dfsg.3~beta1-2ubuntu1.1
intrepid

released

1.6.dfsg.4~beta1-3ubuntu0.1
upstream

released

Показывать по

EPSS

Процентиль: 96%
0.23588
Средний

10 Critical

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.

nvd
больше 16 лет назад

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.

debian
больше 16 лет назад

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c i ...

github
больше 3 лет назад

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.

fstec
больше 16 лет назад

Уязвимость операционной системы CentOS, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 96%
0.23588
Средний

10 Critical

CVSS2