PT-2013-1199 · Mit+1 · Mit Kerberos 5+2

Sol Jerome

·

Publicado

2013-11-20

·

Atualizado

2024-06-15

·

CVE-2013-1417

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (krb5) versions 1.11 through 1.11.3 mit-krb5 versions prior to 1.11.4
Description The issue allows remote authenticated users to cause a denial of service, potentially leading to a disruption in confidentiality, integrity, and availability of protected information. This can be triggered via a TGS-REQ request that causes an attempted cross-realm referral for a host-based service principal when a single-component realm name is used.
Recommendations For MIT Kerberos 5 (krb5) versions 1.11 through 1.11.3, update to version 1.11.4 or later to resolve the issue. For mit-krb5 versions prior to 1.11.4, update to version 1.11.4 or later to resolve the issue.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1539
BDU:2015-09675
CVE-2013-1417
MGASA-2013-0336
OPENSUSE-SU-2024:10004-1

Produtos afetados

Alt Linux
Mit Kerberos 5
Krb5