MIT.Kerberos.ASN.1.Uninitialized.Pointer.Reference
Description
This indicates an attack attempt against a memory-corruption vulnerability in the MIT Kerberos server.
The vulnerability is caused by an error when the vulnerable software decodes maliciously crafted data. It allows a remote attacker to execute arbitrary code.
Affected Products
MIT Kerberos 5 (krb5) versions prior to 1.6.4
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Denial of Service: Remote attackers can crash vulnerable systems.
Recommended Actions
Upgrade to krb5-1.7 or krb5-1.6.4, available from the following web site:
http://web.mit.edu/kerberos/www/dist/index.html
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |