Skip to main content

Kerberos kpasswd UDP Processing Vulnerability

Last Update Date: 16 May 2013 18:34 Release Date: 16 May 2013 4632 Views

RISK: High Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

A vulnerability has been identifitied in MIT Kerberos. A remote user can cause denial of service conditions.

 

A remote user can send spoofed UDP packets to a target kadmind server running kpasswd to cause kpasswd to pass the UDP packets to the spoofed address and reply to the packets, consume excessive CPU resources and bandwidth.

 

This type of exploit is known as a UDP ping-pong attack.


Impact

  • Denial of Service

System / Technologies affected

  • Linux (Any)
  • UNIX (Any)

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link