PT-2011-5243 · Mit+1 · Krb5-Devel+9

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2011-1529

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions 1.8 through 1.8.4 MIT Kerberos 5 versions 1.9 through 1.9.1 krb5 versions prior to 1.9.2 krb5-plugin-kdb-ldap versions (affected versions not specified) krb5-server versions (affected versions not specified) krb5-devel versions (affected versions not specified) krb5-devel-32bit versions (affected versions not specified) krb5-32bit versions (affected versions not specified) krb5-plugin-preauth-pkinit versions (affected versions not specified) krb5-client versions (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the MIT Kerberos 5 package, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. The lookup lockout policy function in the Key Distribution Center (KDC) is specifically vulnerable when using the db2 or LDAP back end, allowing remote attackers to cause a denial of service via certain process as req errors.
Recommendations For MIT Kerberos 5 versions 1.8 through 1.8.4 and 1.9 through 1.9.1, update to a version later than 1.9.1 to resolve the issue. For krb5 versions prior to 1.9.2, update to version 1.9.2 or later. For other affected versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05365
BDU:2015-05366
BDU:2015-05367
BDU:2015-05368
BDU:2015-05369
BDU:2015-05370
BDU:2015-05371
BDU:2015-05372
BDU:2015-09426
CVE-2011-1529
DSA-2379-1
OPENSUSE-SU-2024:10004-1
RHSA-2011:1379
RHSA-2011_1379

Affected Products

Mit Kerberos 5
Red Hat
Krb5
Krb5-32Bit
Krb5-Client
Krb5-Devel
Krb5-Devel-32Bit
Krb5-Plugin-Kdb-Ldap
Krb5-Plugin-Preauth-Pkinit
Krb5-Server