[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SA:2009:019 -- SUSE krb5 remote code execution

ID: oval:org.secpod.oval:def:400089Date: (C)2012-01-31   (M)2024-02-15
Class: PATCHFamily: unix




The Kerberos implementation from MIT is vulnerable to four different security issues that range from a remote crash to to possible, but very unlikely, remote code execution. - CVE-2009-0844: The SPNEGO GSS-API implementation can read beyond the end of a buffer which leads to a crash. - CVE-2009-0845: A NULL pointer dereference in the SPNEGO code can lead to a crash which affects programs using the GSS-API. - CVE-2009-0846: The ASN.1 decoder can free an uninitialized NULL pointer which leads to a crash and can possibly lead to remote code execution. This bug can be exploited before any authen- tication happened, - CVE-2009-0847: The ASN.1 decoder incorrectly validates a length parameter which leads to malloc errors any possibly to a crash.

Platform:
openSUSE 10.3
openSUSE 11.1
openSUSE 11.0
Product:
krb5
Reference:
SUSE-SA:2009:019
CVE-2009-0844
CVE-2009-0845
CVE-2009-0846
CVE-2009-0847
CVE    4
CVE-2009-0844
CVE-2009-0847
CVE-2009-0846
CVE-2009-0845
...
CPE    3
cpe:/o:opensuse:opensuse:11.1
cpe:/o:opensuse:opensuse:11.0
cpe:/o:opensuse:opensuse:10.3

© SecPod Technologies