PT-2016-5374 · Mit+4 · Mit Kerberos 5+4

Greghudson

·

Publicado

2016-08-01

·

Atualizado

2024-06-15

·

CVE-2016-3120

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions prior to 1.13.6 MIT Kerberos 5 versions 1.4.x prior to 1.14.3
Description The issue is related to the validate as request function in kdc util.c within the Key Distribution Center (KDC) of MIT Kerberos 5. When restrict anonymous to tgt is enabled, it incorrectly uses a client data structure. This allows remote authenticated users to cause a denial of service, resulting in a NULL pointer dereference and daemon crash, via an S4U2Self request.
Recommendations For versions prior to 1.13.6, update to version 1.13.6 or later. For versions 1.4.x prior to 1.14.3, update to version 1.14.3 or later.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1166
CESA-2016_2591
CVE-2016-3120
DLA-1265-1
MGASA-2016-0306
OPENSUSE-SU-2024:10004-1
RHSA-2016:2591
RHSA-2016_2591
SUSE-SU-2016:2136-1
SUSE-SU-2016_2136-1

Produtos afetados

Alt Linux
Centos
Mit Kerberos 5
Red Hat
Suse