Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2009-0845 Details

Description

The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://krbdev.mit.edu/rt/Ticket/Display.html?user=guest&pass=guest&id=6402 CVE
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html CVE
http://secunia.com/advisories/34347 CVEVendor Advisory
http://secunia.com/advisories/34594 CVE
http://secunia.com/advisories/34617 CVE

see all 88 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-20Improper Input Validation[email protected]

Affected Products

ProductVersions
mit kerberos
5-1.6.3

CPE

  • cpe:2.3:a:mit:kerberos:5-1.6.3:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
mit kerberos 5
1.5
1.5.1
1.5.2
1.5.3
1.6

CPE

  • cpe:2.3:a:mit:kerberos_5:1.5:*:*:*:*:*:*:*
  • cpe:2.3:a:mit:kerberos_5:1.5.1:*:*:*:*:*:*:*
  • cpe:2.3:a:mit:kerberos_5:1.5.2:*:*:*:*:*:*:*
  • cpe:2.3:a:mit:kerberos_5:1.5.3:*:*:*:*:*:*:*
  • cpe:2.3:a:mit:kerberos_5:1.6:*:*:*:*:*:*:*
  • cpe:2.3:a:mit:kerberos_5:1.6.1:*:*:*:*:*:*:*
  • cpe:2.3:a:mit:kerberos_5:1.6.2:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

15 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2009-0845
NVD Published Date:
Mar 27, 2009
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2009-0845 Details - Not Deferred