CVE-2009-0846

Priority
Description
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the
ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4
allows remote attackers to cause a denial of service (daemon crash) or
possibly execute arbitrary code via vectors involving an invalid DER
encoding that triggers a free of an uninitialized pointer.
Assigned-to
kees
Package
Source: krb5 (LP Ubuntu Debian)
Upstream:released
More Information

Updated: 2019-03-19 11:49:16 UTC (commit 15472795df7e9de45b82f2d36b8b419b939f97b2)