Unrated severityNVD Advisory· Published Jun 7, 2012· Updated Jun 16, 2026
CVE-2012-1013
CVE-2012-1013
Description
The check_1_6_dummy function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x, and 1.10.x before 1.10.2 allows remote authenticated administrators to cause a denial of service (NULL pointer dereference and daemon crash) via a KRB5_KDB_DISALLOW_ALL_TIX create request that lacks a password.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15cpe:2.3:a:mit:kerberos_5:1.10:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:mit:kerberos_5:1.10:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.8:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.8.5:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.8.6:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.9:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.9.3:*:*:*:*:*:*:*
- (no CPE)range: >=1.8.0, <1.10.2
Patches
Vulnerability mechanics
References
9- github.com/krb5/krb5/commit/c5be6209311d4a8f10fda37d0d3f876c1b33b77bnvdExploitPatch
- krbdev.mit.edu/rt/Ticket/Display.htmlnvd
- mailman.mit.edu/pipermail/kerberos-announce/2012q2/000136.htmlnvd
- rhn.redhat.com/errata/RHSA-2012-1131.htmlnvd
- web.mit.edu/kerberos/krb5-1.10/nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/53784nvd
- bugzilla.redhat.com/show_bug.cginvd
- hermes.opensuse.org/messages/15083635nvd
News mentions
0No linked articles in our index yet.