CVE-2010-0433
CVE-2010-0433
The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory.aschttp://cvs.openssl.org/chngview?cn=19374http://groups.google.com/group/mailing.openssl.users/browse_thread/thread/c3e1ab0034ca4b4c/66aa896c3a78b2f7http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.htmlhttp://marc.info/?l=bugtraq&m=127128920008563&w=2http://marc.info/?l=bugtraq&m=127557640302499&w=2https://bugzilla.redhat.com/show_bug.cgi?id=567711https://bugzilla.redhat.com/show_bug.cgi?id=569774http://secunia.com/advisories/39461http://secunia.com/advisories/39932http://secunia.com/advisories/42724