Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kerberos_5 | Mit | 1.2.1 (including) | 1.2.1 (including) |
Kerberos_5 | Mit | 1.2.2 (including) | 1.2.2 (including) |
Kerberos_5 | Mit | 1.2.3 (including) | 1.2.3 (including) |
Kerberos_5 | Mit | 1.2.4 (including) | 1.2.4 (including) |