Mandriva Linux Security Advisory 2009-082 – The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token. This update provides the fix for that security issue.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/76177/MDVSA-2009-082.txt
Source: https://packetstormsecurity.com/files/76177/Mandriva-Linux-Security-Advisory-2009-082.html

