Description
The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x before 1.10.3 attempts to calculate a checksum before verifying that the key type is appropriate for a checksum, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free, heap memory corruption, and daemon crash) via a crafted AS-REQ request.
References (5)
Core 5
Core References
Patch, Vendor Advisory x_refsource_confirm
http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2012-001.txt
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1131.html
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-08/msg00016.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2012/dsa-2518
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2012:120
Scores
EPSS
0.0123
EPSS Percentile
79.4%
Details
CWE
CWE-20
Status
published
Products (11)
mit/kerberos_5
1.8
mit/kerberos_5
1.8.1
mit/kerberos_5
1.8.2
mit/kerberos_5
1.8.3
mit/kerberos_5
1.8.4
mit/kerberos_5
1.8.5
mit/kerberos_5
1.8.6
mit/kerberos_5
1.9.4
mit/kerberos_5
1.10
mit/kerberos_5
1.10.1
... and 1 more
Published
Aug 06, 2012
Tracked Since
Feb 18, 2026