PT-2015-5837 · Mit+5 · Mit Kerberos 5+5

Greg Hudson

·

Published

2015-05-25

·

Updated

2024-06-15

·

CVE-2015-2694

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions 1.12.x through 1.13.1
Description The issue allows remote attackers to bypass an intended preauthentication requirement. This can be achieved by providing either zero bytes of data or an arbitrary realm name. The problem is related to the kdcpreauth modules in MIT Kerberos 5, specifically in the plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit srv.c files.
Recommendations For versions 1.12.x through 1.13.1, update to version 1.13.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the kdcpreauth modules until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1898
CESA-2015_2154
CVE-2015-2694
OPENSUSE-SU-2024:10004-1
RHSA-2015:2154
RHSA-2015_2154
SUSE-SU-2015:1276-1
USN-2810-1

Affected Products

Alt Linux
Centos
Mit Kerberos 5
Red Hat
Suse
Ubuntu