The kssl_keytab_is_available function in ssl/kssl.c in...
Moderate severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Feb 21, 2023
Description
Published by the National Vulnerability Database
Mar 5, 2010
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Feb 21, 2023
The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.
References