Vulnerability Description
Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mit | Kerberos | 5-1.6.3 |
| Mit | Kerberos 5 | 1.3 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033915.ht
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033919.ht
- http://marc.info/?l=bugtraq&m=130497213107107&w=2
- http://secunia.com/advisories/38080
- http://secunia.com/advisories/38108
- http://secunia.com/advisories/38126
- http://secunia.com/advisories/38140
- http://secunia.com/advisories/38184
- http://secunia.com/advisories/38203
- http://secunia.com/advisories/38696
- http://secunia.com/advisories/40220
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-275530-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021779.1-1
- http://support.apple.com/kb/HT4188
FAQ
What is CVE-2009-4212?
CVE-2009-4212 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to ca...
How severe is CVE-2009-4212?
CVE-2009-4212 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4212?
Check the references section above for vendor advisories and patch information. Affected products include: Mit Kerberos, Mit Kerberos 5.