Description: A vulnerability has been reported in Kerberos, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
The vulnerability is caused due to an error in the handling of xprt->xp_auth pointers when freeing structures in memory. This can be exploited to crash the daemon or execute arbitrary code via a specially crafted kerberos packet.
The vulnerability is reported in the following versions:
* krb5-1.4 through krb5-1.4.4
* krb5-1.5 through krb5-1.5.1
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.