VYPR
Unrated severityNVD Advisory· Published Mar 5, 2013· Updated Apr 29, 2026

CVE-2012-1016

CVE-2012-1016

Description

The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 attempts to find an agility KDF identifier in inappropriate circumstances, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted Draft 9 request.

Affected products

1
  • cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*
    Range: <1.10.4

Patches

1
db64ca25d661

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

4

News mentions

0

No linked articles in our index yet.