The process_as_req function in the Key Distribution Center (KDC) in MIT
Kerberos 5 (aka krb5) 1.10.x before 1.10.3 does not initialize a certain
structure member, which allows remote attackers to cause a denial of
service (uninitialized pointer dereference and daemon crash) or possibly
execute arbitrary code via a malformed AS-REQ request.
sbeattie> krb5 1.10 and newer
sbeattie> code execution potential probably blocked by glibc
Updated: 2015-07-29 20:40:30 UTC (commit 9756)