CVE-2009-0845
The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token.
Published:Mar 13, 2009
Last Modified:Apr 23, 2026
EPS:Mar 27, 2009
EPSS Score:0.19309
CVSS Score:5
Affected Products
Vendor
Product
Action
Vendor
Mit
Product
Kerberos
Mit
Kerberos
Vendor
Mit
Product
Kerberos 5
Mit
Kerberos 5
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
