Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-0284

EPSS 22.64% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-0284

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Double free vulnerability in the prepare_error_as function in do_as_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 through 1.9, when the PKINIT feature is enabled, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an e_data field containing typed data.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
MIT Kerberos KDC 'do_as_req.c'双重释放内存破坏漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Kerberos是一款广泛使用的超强加密来验证客户端和服务器端的网络协议。 MIT Kerberos在"do_as_req.c"的实现上存在远程内存破坏漏洞,攻击者可利用此漏洞以超级用户的权限,借助包含类型化数据的e_data字段,执行任意代码,完全控制受影响计算机,造成拒绝服务。 如果krb5-1.7或较高版本的KDC配置为响应PKINIT请求,即启用了"初始验证公开密钥加密"PKINIT功能,就会受到双重释放内存破坏漏洞的影响,造成程序崩溃或执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-0284

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-0284

登录查看更多情报信息。

Same Patch Batch · n/a · 2011-03-20 · 15 CVEs total

CVE-2011-0421PHP Zip扩展_zip_name_locate函数拒绝服务漏洞
CVE-2011-0708PHP Exif扩展exif.c拒绝服务漏洞
CVE-2011-1024OpenLDAP back-ldap chain.c外部程序认证绕过漏洞
CVE-2011-1025OpenLDAP back-ndb bind.cpp访问限制绕过漏洞
CVE-2011-1027Lars_Hjemli cgit convert_query_hexchar函数无限循环拒绝服务漏洞
CVE-2011-1081OpenLDAP slapd modrdn.c拒绝服务漏洞
CVE-2011-1464PHP strval函数缓冲区溢出漏洞
CVE-2011-1465Google Chrome net/http/http_network_transaction.cc SPDY实现拒绝服务漏洞
CVE-2011-1466PHP Calendar SdnToJulian函数整数溢出漏洞
CVE-2011-1467PHP Intl扩展NumberFormatter::setSymbol函数拒绝服务漏洞
CVE-2011-1468PHP OpenSSL扩展多个内存泄露漏洞
CVE-2011-1469PHP Streams组件拒绝服务漏洞
CVE-2011-1470PHP Zip扩展拒绝服务漏洞
CVE-2011-1471PHP Zip扩展zip_stream.c整数符号错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2011-0284

No comments yet


Leave a comment