UBUNTU-CVE-2012-1016
Dashboard / Vulnerabilities / UBUNTU-CVE-2012-1016
UBUNTU-CVE-2012-1016
Summary:
Details: The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 attempts to find an agility KDF identifier in inappropriate circumstances, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted Draft 9 request.
References: https://ubuntu.com/security/CVE-2012-1016, http://web.mit.edu/kerberos/www/krb5-1.10/, https://ubuntu.com/security/notices/USN-2310-1, https://www.cve.org/CVERecord?id=CVE-2012-1016
Affected packages
Package
Name: krb5
Purl: pkg:deb/ubuntu/[email protected]+dfsg-3ubuntu2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
