MIT.Kerberos.ASN.1.Uninitialized.Pointer.Reference

description-logoDescription

This indicates an attack attempt against a memory-corruption vulnerability in the MIT Kerberos server.
The vulnerability is caused by an error when the vulnerable software decodes maliciously crafted data. It allows a remote attacker to execute arbitrary code.

affected-products-logoAffected Products

MIT Kerberos 5 (krb5) versions prior to 1.6.4

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.
Denial of Service: Remote attackers can crash vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade to krb5-1.7 or krb5-1.6.4, available from the following web site:
http://web.mit.edu/kerberos/www/dist/index.html

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)