CERT-In Vulnerability Note
CIVN-2012-0103
Vulnerability in Kerberos Could Allow Denial of Service
Original Issue Date:October 10, 2012
Severity Rating: MEDIUM
Systems Affected
- Windows 7 for 32-bit Systems and Service Pack 1
- Windows 7 for x64-based Systems and Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems and Service Pack 1
- Windows Server 2008 R2 for Itanium-based Systems and Service Pack 1
- Windows Server 2008 R2 for x64-based Systems and Service Pack 1
Overview
The vulnerability has been reported in Microsoft Windows Kerberos, which could be exploited by a remote attacker to cause a DOS condition.
Description
This vulnerability exists because the affected software improperly attempts to dereference a NULL pointer when handling crafted Kerberos sessions. When the NULL pointer is dereferenced, a memory error condition could occur that could cause the system to stop responding and terminate abnormally.
A remote attacker could exploit this vulnerability to cause the system to stop responding to the legitimate user requests and terminate abnormally, resulting in Denial of Service (DoS) condition.
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin
MS12-069
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-069
References
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=27092
CVE Name
CVE-2012-2551
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|