CVE-2013-1418 (retired)

Priority
Description
The setup_server_realm function in main.c in the Key Distribution Center
(KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are
configured, allows remote attackers to cause a denial of service (NULL
pointer dereference and daemon crash) via a crafted request.
Assigned-to
mdeslaur
Package
Source: krb5 (LP Ubuntu Debian)
Upstream:released (1.10.7)
Ubuntu 14.04 ESM (Trusty Tahr):not-affected (1.12+dfsg-2ubuntu4)
Patches:
Upstream:https://github.com/krb5/krb5/commit/5d2d9a1abe46a2c1a8614d4672d08d9d30a5f8bf (1.12)
Upstream:https://github.com/krb5/krb5/commit/c2ccf4197f697c4ff143b8a786acdd875e70a89d (1.10.7)
Binaries built from this source package are in universe and so are supported by the community. For more details see https://wiki.ubuntu.com/SecurityTeam/FAQ#Official_Support
More Information

Updated: 2019-09-19 15:43:43 UTC (commit d32ebc32606b9517c6fa7d65a15441e2a57a6de5)