Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-0433

Опубликовано: 05 мар. 2010
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.

РелизСтатусПримечание
dapper

not-affected

no kerberos support
devel

not-affected

no kerberos support
hardy

not-affected

no kerberos support
intrepid

not-affected

no kerberos support
jaunty

not-affected

no kerberos support
karmic

not-affected

no kerberos support
upstream

released

0.9.8n

Показывать по

Ссылки на источники

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 15 лет назад

The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.

nvd
больше 15 лет назад

The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.

debian
больше 15 лет назад

The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before ...

github
больше 3 лет назад

The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.

oracle-oval
больше 15 лет назад

ELSA-2010-0162: openssl security update (IMPORTANT)

4.3 Medium

CVSS2