CVE-2009-0847

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 09 Apr 2009, 00:00
Last modified:07 Aug 2024, 04:48

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
20.29% HIGH
20% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Apr 2009, 00:00
Published
Vulnerability first disclosed
07 Aug 2024, 04:48
Last Modified
Vulnerability information updated

Description

The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 20.29% Percentile: 96%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • mitkerberos

    5-1.6.3

References (38)