PT-2016-3940 · Mit+4 · Mit Kerberos 5+4

Greg Hudson

·

Published

2016-02-04

·

Updated

2024-06-15

·

CVE-2015-8630

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (aka krb5) versions 1.12.x through 1.13.x before 1.13.4 MIT Kerberos 5 (aka krb5) versions 1.14.x before 1.14.1
Description The issue allows remote authenticated users to cause a denial of service, resulting in a daemon crash due to a NULL pointer dereference. This occurs when the KADM5 POLICY is specified with a NULL policy name, affecting the kadm5 create principal 3 and kadm5 modify principal functions.
Recommendations For versions 1.12.x through 1.13.x before 1.13.4, update to version 1.13.4 or later. For versions 1.14.x before 1.14.1, update to version 1.14.1 or later. As a temporary workaround, consider restricting access to the kadm5 create principal 3 and kadm5 modify principal functions until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2016-1392
CESA-2016_0532
CVE-2015-8630
DSA-3466-1
MGASA-2016-0052
OPENSUSE-SU-2024:10004-1
RHSA-2016:0532
RHSA-2016_0532
SUSE-SU-2016:0429-1

Affected Products

Alt Linux
Centos
Mit Kerberos 5
Red Hat
Suse