PT-2013-1201 · Mit+3 · Mit Kerberos 5+3

Published

2013-11-16

·

Updated

2020-01-21

·

CVE-2013-6800

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (aka krb5) versions 1.10.x through 1.11.3
Description The issue affects the Key Distribution Center (KDC) in MIT Kerberos 5 due to an unspecified third-party database module. It allows remote authenticated users to cause a denial of service via a crafted request, resulting in a NULL pointer dereference and daemon crash. Additionally, multiple vulnerabilities in the mit-krb5 package prior to version 1.11.4 may lead to breaches of confidentiality, integrity, and availability of protected information, with potential for remote exploitation.
Recommendations For versions 1.10.x through 1.11.3, update to version 1.11.4 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09675
CESA-2014_1389
CVE-2013-6800
RHSA-2014:1245
RHSA-2014:1389
RHSA-2014_1245
RHSA-2014_1389
USN-2310-1

Affected Products

Centos
Mit Kerberos 5
Red Hat
Ubuntu