PT-2013-1201 · Mit+3 · Mit Kerberos 5+3
Published
2013-11-16
·
Updated
2020-01-21
·
CVE-2013-6800
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MIT Kerberos 5 (aka krb5) versions 1.10.x through 1.11.3
Description
The issue affects the Key Distribution Center (KDC) in MIT Kerberos 5 due to an unspecified third-party database module. It allows remote authenticated users to cause a denial of service via a crafted request, resulting in a NULL pointer dereference and daemon crash. Additionally, multiple vulnerabilities in the mit-krb5 package prior to version 1.11.4 may lead to breaches of confidentiality, integrity, and availability of protected information, with potential for remote exploitation.
Recommendations
For versions 1.10.x through 1.11.3, update to version 1.11.4 or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific vulnerability.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Mit Kerberos 5
Red Hat
Ubuntu