PT-2013-1201 · Mit+3 · Mit Kerberos 5+3

Publicado

2013-11-16

·

Atualizado

2020-01-21

·

CVE-2013-6800

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (aka krb5) versions 1.10.x through 1.11.3
Description The issue affects the Key Distribution Center (KDC) in MIT Kerberos 5 due to an unspecified third-party database module. It allows remote authenticated users to cause a denial of service via a crafted request, resulting in a NULL pointer dereference and daemon crash. Additionally, multiple vulnerabilities in the mit-krb5 package prior to version 1.11.4 may lead to breaches of confidentiality, integrity, and availability of protected information, with potential for remote exploitation.
Recommendations For versions 1.10.x through 1.11.3, update to version 1.11.4 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09675
CESA-2014_1389
CVE-2013-6800
RHSA-2014:1245
RHSA-2014:1389
RHSA-2014_1245
RHSA-2014_1389
USN-2310-1

Produtos afetados

Centos
Mit Kerberos 5
Red Hat
Ubuntu