libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of service (daemon exit) via a GSS-TSIG request. NOTE: this issue probably affects other daemons that attempt to initialize this library within a chroot configuration or other invalid configuration.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Suse_linux | Suse | 10-sp1 (including) | 10-sp1 (including) |
Libgssapi | Ubuntu | dapper | * |
Libgssapi | Ubuntu | edgy | * |
Libgssapi | Ubuntu | feisty | * |
Libgssapi | Ubuntu | gutsy | * |