CVE-2006-5989

Publication date 20 November 2006

Last updated 24 July 2024


Ubuntu priority

Off-by-one error in the der_get_oid function in mod_auth_kerb 5.0 allows remote attackers to cause a denial of service (crash) via a crafted Kerberos message that triggers a heap-based buffer overflow in the component array.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
libapache-mod-auth-kerb 7.04 feisty
Fixed 5.3-1ubuntu2
6.10 edgy
Fixed 4.996-5.0-rc6-3ubuntu0.6.10
6.06 LTS dapper
Fixed 4.996-5.0-rc6-3ubuntu0.6.06