SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  MIT Kerberos kpasswd Service DoS

Category: MISC      

schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2443


Relevant Information