PT-2011-5243 · Mit+1 · Krb5-Devel+9
Published
1970-01-01
·
Updated
2024-06-15
·
CVE-2011-1529
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
MIT Kerberos 5 versions 1.8 through 1.8.4
MIT Kerberos 5 versions 1.9 through 1.9.1
krb5 versions prior to 1.9.2
krb5-plugin-kdb-ldap versions (affected versions not specified)
krb5-server versions (affected versions not specified)
krb5-devel versions (affected versions not specified)
krb5-devel-32bit versions (affected versions not specified)
krb5-32bit versions (affected versions not specified)
krb5-plugin-preauth-pkinit versions (affected versions not specified)
krb5-client versions (affected versions not specified)
Description
The issue is related to multiple vulnerabilities in the MIT Kerberos 5 package, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. The
lookup lockout policy function in the Key Distribution Center (KDC) is specifically vulnerable when using the db2 or LDAP back end, allowing remote attackers to cause a denial of service via certain process as req errors.Recommendations
For MIT Kerberos 5 versions 1.8 through 1.8.4 and 1.9 through 1.9.1, update to a version later than 1.9.1 to resolve the issue.
For krb5 versions prior to 1.9.2, update to version 1.9.2 or later.
For other affected versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
RCE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mit Kerberos 5
Red Hat
Krb5
Krb5-32Bit
Krb5-Client
Krb5-Devel
Krb5-Devel-32Bit
Krb5-Plugin-Kdb-Ldap
Krb5-Plugin-Preauth-Pkinit
Krb5-Server