Check Point Reference: | CPAI-2013-2942 |
Date Published: | 27 Oct 2013 |
Severity: | High |
Last Updated: | Saturday 04 January, 2025 |
Source: | CVE-2005-1174 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | MIT Kerberos Project Kerberos |
Vulnerability Description | There exists a heap corruption vulnerability in the MIT Kerberos V5 Key Distribution Center (KDC) implementation. |
Vulnerability Details | The vulnerability is caused due to improper handling of an error case that results in heap corruption. An unauthenticated remote attacker can leverage this vulnerability to cause a denial of service or to execute arbitrary code, potentially compromising an entire Kerberos realm. |
The protection will detect and block attempts to exploit this vulnerability.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
SmartView Tracker will log the following entries:
Attack Name: Application Servers Protection Violation
Attack Information: MIT Kerberos V5 KDC TCP Handling Denial of Service