CVE-2012-1016

Priority
Medium
Description
The pkinit_server_return_padata function in
plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key
Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4
attempts to find an agility KDF identifier in inappropriate circumstances,
which allows remote attackers to cause a denial of service (NULL pointer
dereference and daemon crash) via a crafted Draft 9 request.
References
Bugs
Assigned-to
mdeslaur
Package
Source: krb5 (LP Ubuntu Debian)
Upstream:released (1.10.4,1.10.1+dfsg-4+nmu1)
Ubuntu 10.04 LTS (Lucid Lynx):not-affected (code not present)
Ubuntu 12.04 LTS (Precise Pangolin):released (1.10+dfsg~beta1-2ubuntu0.5)
Ubuntu 14.04 LTS (Trusty Tahr):not-affected (1.11.3+dfsg-3ubuntu2)
Ubuntu 14.10 (Utopic Unicorn):not-affected (1.11.3+dfsg-3ubuntu2)
Patches:
Upstream:https://github.com/krb5/krb5/commit/db64ca25d661a47b996b4e2645998b5d7f0eb52c
More Information

Valid XHTML 1.0 Strict

Updated: 2014-08-11 14:14:42 UTC (commit 8348)