In Zeek Network Security Monitor (formerly known as Bro) before 2.6.2, a NULL pointer dereference in the Kerberos (aka KRB) protocol parser leads to DoS because a case-type index is mishandled.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Zeek | Zeek | * | 2.6.2 (excluding) |
| Bro | Ubuntu | bionic | * |
| Bro | Ubuntu | trusty | * |
| Bro | Ubuntu | upstream | * |
| Bro | Ubuntu | xenial | * |