Input validation error in Kerberos 5 - CVE-2011-0283
Published: February 10, 2011 / Updated: May 27, 2022
Kerberos 5
Detailed vulnerability description
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request packet that does not trigger a response packet.
How to mitigate CVE-2011-0283
Sources
- http://secunia.com/advisories/43260
- http://securityreason.com/securityalert/8073
- http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-002.txt
- http://www.securityfocus.com/archive/1/516299/100/0/threaded
- http://www.securityfocus.com/bid/46272
- http://www.securitytracker.com/id?1025037
- http://www.vupen.com/english/advisories/2011/0330