Saturday, October 9, 2010

Kerberos: denial of service vulnerability

Users of Kerberos please be advised of a denial of service vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
USN-999-1: [USN-999-1] Kerberos vulnerability
Details follow:



Mike Roszkowski discovered that the Kerberos KDC did not correctly

validate the contents of certain messages. If an authenticated remote

attacker sent specially crafted TGS requests, the KDC service would crash,

leading to a denial of service.
Read more at www.criticalwatch.com
 

No comments:

Post a Comment