CVE-2009-0846
EPSS 51.9%
Description
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
How to fix CVE-2009-0846
To remediate CVE-2009-0846, upgrade the affected package to a fixed version below.
- Debian/krb5—upgrade to 1.6.dfsg.4~beta1-13 or later
Is CVE-2009-0846 being exploited?
Likely — EPSS is 51.9%, placing CVE-2009-0846 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 1.6.dfsg.4~beta1-13