PublicDate: 2006-11-20 21:07:00 UTC Candidate: CVE-2006-5989 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5989 Description: Off-by-one error in the der_get_oid function in mod_auth_kerb 5.0 allows remote attackers to cause a denial of service (crash) via a crafted Kerberos message that triggers a heap-based buffer overflow in the component array. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_libapache-mod-auth-kerb: released (4.996-5.0-rc6-3ubuntu0.6.06) edgy_libapache-mod-auth-kerb: released (4.996-5.0-rc6-3ubuntu0.6.10) feisty_libapache-mod-auth-kerb: released (5.3-1ubuntu2) devel_libapache-mod-auth-kerb: released (5.3-1ubuntu2) upstream_libapache-mod-auth-kerb: needs-triage