Cisco-SA-20100519-CVE-2010-1321
MIT Kerberos GSS-API Library Remote Denial of Service Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
MIT Kerberos contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is in the GSS-API acceptor component due to lack of pointer validation. An authenticated, remote attacker could exploit the vulnerability by making a crafted request to the affected component. This action could cause the component to crash, resulting in a DoS condition. MIT has confirmed this vulnerability and released updated software. The vulnerability can be exploited only by an authenticated attacker, which somewhat reduces the threat of an attack on affected systems. Cisco Network Admission Control Guest Server may be affected if Active Directory single sign-on is enabled.