Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-0846

32
FAUCET Score

CVE-2009-0846 is a critical vulnerability in the ASN.1 GeneralizedTime decoder within MIT Kerberos 5 (krb5) versions prior to 1.6.4, affecting products from vendors like Apple, Canonical, Fedora Project, MIT, and Red Hat. This flaw allows remote, unauthenticated attackers to cause a denial of service (daemon crash) or potentially execute arbitrary code by sending a specially crafted, invalid DER encoding that triggers a free of an uninitialized pointer. With a CVSS score of 10.0 and a FAUCET Risk Score of 98/100, its severity is extremely high due to the network-based attack vector, low attack complexity, and complete impact on confidentiality, integrity, and availability. Despite its age and high severity, there is no known active exploitation, publicly available exploit code in Metasploit or ExploitDB, nor significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.6.4CPE matchmatch criteria
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*
9CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*
10CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
7.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

10.0HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
8.90%
Probability of exploitation in next 30 days
EPSS Percentile
94.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0890 is in the 91st percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: krb5-0:1.2.2-49
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: krb5-0:1.2.7-70
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: krb5-0:1.3.4-60.el4_7.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: krb5-0:1.6.1-31.el5_3.3
View patch

Vendor Advisories (1)

redhatCVE-2009-0846Critical

krb5: ASN.1 decoder can free uninitialized pointer when decoding an invalid encoding (MITKRB5-SA-2009-002)

Apr 7, 2009

References

lists.apple.com / archives/security-announce/2009/May/msg00002.html
Mailing List
lists.vmware.com / pipermail/security-announce/2009/000059.html
Broken Link
marc.info
Third Party Advisory
marc.info
Third Party Advisory
rhn.redhat.com / errata/RHSA-2009-0409.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2009-0410.html
Third Party Advisory
secunia.com / advisories/34594
Broken Link
secunia.com / advisories/34598
Broken Link
secunia.com / advisories/34617
Broken Link
secunia.com / advisories/34622
Broken Link
secunia.com / advisories/34628
Broken Link
secunia.com / advisories/34630
Broken Link
secunia.com / advisories/34637
Broken Link
secunia.com / advisories/34640
Broken Link
secunia.com / advisories/34734
Broken Link
secunia.com / advisories/35074
Broken Link
secunia.com / advisories/35667
Broken Link
security.gentoo.org / glsa/glsa-200904-09.xml
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10694
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5483
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6301
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
support.apple.com / kb/HT3549
Third Party Advisory
support.avaya.com / elmodocs2/security/ASA-2009-142.htm
Third Party Advisory
support.novell.com / docs/Readmes/InfoDocument/patchbuilder/readme_5047180.html
Broken Link
support.novell.com / docs/Readmes/InfoDocument/patchbuilder/readme_5047181.html
Broken Link
redhat.com / archives/fedora-package-announce/2009-April/msg00205.html
Mailing List
redhat.com / archives/fedora-package-announce/2009-April/msg00206.html
Mailing List
web.mit.edu / kerberos/advisories/MITKRB5-SA-2009-002.txt
PatchVendor Advisory
wiki.rpath.com / Advisories:rPSA-2009-0058
Broken Link
wiki.rpath.com / wiki/Advisories:rPSA-2009-0058
Broken Link
www-01.ibm.com / support/docview.wss
Broken Link
kb.cert.org / vuls/id/662091
Broken LinkThird Party AdvisoryUS Government Resource
mandriva.com / security/advisories
Broken Link
redhat.com / support/errata/RHSA-2009-0408.html
Broken Link
securityfocus.com / archive/1/502527/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/502546/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/504683/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/34409
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/usn-755-1
Third Party Advisory
us-cert.gov / cas/techalerts/TA09-133A.html
Third Party AdvisoryUS Government Resource
vmware.com / security/advisories/VMSA-2009-0008.html
Third Party Advisory
vupen.com / english/advisories/2009/0960
Broken Link
vupen.com / english/advisories/2009/0976
Broken Link
vupen.com / english/advisories/2009/1057
Broken Link
vupen.com / english/advisories/2009/1106
Broken Link
vupen.com / english/advisories/2009/1297
Broken Link
vupen.com / english/advisories/2009/2084
Broken Link
vupen.com / english/advisories/2009/2248
Broken Link