DEBIAN-CVE-2012-1013

Source
https://security-tracker.debian.org/tracker/CVE-2012-1013
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2012-1013.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2012-1013
Upstream
Published
2012-06-07T19:55:07.930Z
Modified
2025-11-19T01:01:58.493463Z
Summary
[none]
Details

The check16dummy function in lib/kadm5/srv/svrprincipal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x, and 1.10.x before 1.10.2 allows remote authenticated administrators to cause a denial of service (NULL pointer dereference and daemon crash) via a KRB5KDBDISALLOWALLTIX create request that lacks a password.

References

Affected packages

Debian:11 / krb5

Package

Name
krb5
Purl
pkg:deb/debian/krb5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1+dfsg-3

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / krb5

Package

Name
krb5
Purl
pkg:deb/debian/krb5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1+dfsg-3

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / krb5

Package

Name
krb5
Purl
pkg:deb/debian/krb5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1+dfsg-3

Ecosystem specific

{
    "urgency": "low"
}

Debian:14 / krb5

Package

Name
krb5
Purl
pkg:deb/debian/krb5?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1+dfsg-3

Ecosystem specific

{
    "urgency": "low"
}