MIT Kerberos GSS-API Checksum NULL Pointer Dereference Denial Of Service Vulnerability
13 Apr. 2012
Summary
This allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.
MIT Kerberos is prone to a remote denial-of-service vulnerability caused by a NULL-pointer dereference in the GSS-API library. An attacker may exploit this issue to crash the kadmind service, resulting in denial-of-service conditions. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Vendor Status:
Oracle as issued an update for this vulnerablity