CVE-2012-1016 (retired)

Priority
Description
The pkinit_server_return_padata function in
plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key
Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4
attempts to find an agility KDF identifier in inappropriate circumstances,
which allows remote attackers to cause a denial of service (NULL pointer
dereference and daemon crash) via a crafted Draft 9 request.
Assigned-to
mdeslaur
Package
Source: krb5 (LP Ubuntu Debian)
Upstream:released (1.10.4,1.10.1+dfsg-4+nmu1)
Ubuntu 14.04 ESM (Trusty Tahr):not-affected (1.11.3+dfsg-3ubuntu2)
Patches:
Upstream:https://github.com/krb5/krb5/commit/db64ca25d661a47b996b4e2645998b5d7f0eb52c
Binaries built from this source package are in universe and so are supported by the community. For more details see https://wiki.ubuntu.com/SecurityTeam/FAQ#Official_Support
More Information

Updated: 2019-09-19 15:39:40 UTC (commit d32ebc32606b9517c6fa7d65a15441e2a57a6de5)