PT-2015-5839 · Mit+3 · Mit Kerberos 5+3

Nicolas Williams

·

Published

2015-10-30

·

Updated

2024-06-15

·

CVE-2015-2696

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (krb5) versions prior to 1.14
Description The issue allows remote attackers to cause a denial of service, resulting in an incorrect pointer read and process crash. This occurs when a crafted IAKERB packet is mishandled during a gss inquire context call, due to reliance on an inappropriate context handle.
Recommendations For versions prior to 1.14, update to version 1.14 or later to resolve the issue.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1392
CVE-2015-2696
DSA-3395-1
MGASA-2015-0436
OPENSUSE-SU-2015_1928-1
OPENSUSE-SU-2015_1997-1
OPENSUSE-SU-2024:10004-1
SUSE-SU-2015:1897-1
USN-2810-1

Affected Products

Alt Linux
Mit Kerberos 5
Suse
Ubuntu