Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2010-0433

Published: 5 March 2010

The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.

Notes

AuthorNote
mdeslaur
Ubuntu doesn't build openssl with kerberos support

Priority

Medium

Status

Package Release Status
openssl
Launchpad, Ubuntu, Debian
dapper Not vulnerable
(no kerberos support)
hardy Not vulnerable
(no kerberos support)
intrepid Not vulnerable
(no kerberos support)
jaunty Not vulnerable
(no kerberos support)
karmic Not vulnerable
(no kerberos support)
upstream
Released (0.9.8n)
Patches:
upstream: http://cvs.openssl.org/chngview?cn=19374