PT-2011-1144 · Mit+1 · Mit Kerberos 5+1

Felipe Ortega

·

Published

2011-04-14

·

Updated

2024-06-15

·

CVE-2011-0285

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions 1.7 through 1.9 krb5-server-1.8.2 krb5-libs-1.8.2 krb5-devel-1.8.2 krb5-server-ldap-1.8.2 krb5-pkinit-openssl-1.8.2 krb5-1.8.2 krb5-debuginfo-1.8.2 krb5-workstation-1.8.2
Description The vulnerability can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information. The process chpw request function in schpw.c in the password-changing functionality in kadmind frees an invalid pointer, allowing remote attackers to execute arbitrary code or cause a denial of service.
Recommendations For MIT Kerberos 5 versions 1.7 through 1.9, update to a version later than 1.9 to resolve the issue. For krb5-server-1.8.2, krb5-libs-1.8.2, krb5-devel-1.8.2, krb5-server-ldap-1.8.2, krb5-pkinit-openssl-1.8.2, krb5-1.8.2, krb5-debuginfo-1.8.2, and krb5-workstation-1.8.2, consider disabling the password-changing functionality in kadmind until a patch is available. As a temporary workaround, restrict access to the vulnerable process chpw request function in schpw.c to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07293
BDU:2015-07300
BDU:2015-07305
BDU:2015-07310
BDU:2015-07312
BDU:2015-07317
BDU:2015-07320
BDU:2015-07325
BDU:2015-09426
CVE-2011-0285
OPENSUSE-SU-2024:10004-1
RHSA-2011:0447
RHSA-2011_0447

Affected Products

Mit Kerberos 5
Red Hat