Total vulnerabilities in the database
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.
Software | From | Fixed in |
---|---|---|
mit / kerberos_5 | - | 1.6.3.x |
debian / debian_linux | 3.1 | 3.1.x |
debian / debian_linux | 4.0 | 4.0.x |
canonical / ubuntu_linux | 7.04 | 7.04.x |
canonical / ubuntu_linux | 7.10 | 7.10.x |
canonical / ubuntu_linux | 6.10 | 6.10.x |
canonical / ubuntu_linux | 6.06 | 6.06.x |
fedoraproject / fedora | 8 | 8.x |
fedoraproject / fedora | 7 | 7.x |