CVE-2011-1530 | Date: (C)2011-12-08 (M)2023-12-22 |
The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS request that triggers an error other than the KRB5_KDB_NOENTRY error.
CVSS Score and Metrics +CVSS Score and Metrics -CVSS V2 Severity: |
CVSS Score : 6.8 |
Exploit Score: 8.0 |
Impact Score: 6.9 |
|
CVSS V2 Metrics: |
Access Vector: NETWORK |
Access Complexity: LOW |
Authentication: SINGLE |
Confidentiality: NONE |
Integrity: NONE |
Availability: COMPLETE |
| |