Public Date:
917840: CVE-2012-1016 krb5: PKINIT null pointer deref leads to DoS

The MITRE CVE dictionary describes this issue as:

The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 attempts to find an agility KDF identifier in inappropriate circumstances, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted Draft 9 request.

Find out more about CVE-2012-1016 from the MITRE CVE dictionary dictionary and NIST NVD.


This issue did not affect the versions of krb5 as shipped with Red Hat Enterprise Linux 5 as they did not include support for PKINIT.

CVSS v2 metrics

NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux version 6 (krb5) RHSA-2013:0656 2013-03-18

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 5 krb5 Not affected
Red Hat Enterprise Linux 4 krb5 Not affected

External References