suse · CVE-2009-0846

Quick triage

Priority: critical Published: 2021-05-30 12:46:14 UTC Updated: 2026-04-18 20:21:47 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2009-0846 severity critical: SUSE including 115 source package names (krb5-1.12.1-19.1, krb5-1.12.1-6.3, …), 170 product×package rows across 34 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (34 product lines)): Fixed 170.

Description:

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.

cvelogic Threat Intelligence