Off-by-one error in the der_get_oid function in mod_auth_kerb 5.0 allows remote attackers to cause a denial of service (crash) via a crafted Kerberos message that triggers a heap-based buffer overflow in the component array.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mod_auth_kerb | Mod_auth_kerb | 5.0 (including) | 5.0 (including) |
Red Hat Enterprise Linux 4 | RedHat | mod_auth_kerb-0:5.0-1.3 | * |
Libapache-mod-auth-kerb | Ubuntu | dapper | * |
Libapache-mod-auth-kerb | Ubuntu | devel | * |
Libapache-mod-auth-kerb | Ubuntu | edgy | * |
Libapache-mod-auth-kerb | Ubuntu | feisty | * |