PT-2017-13867 · Mit+2 · Mit Kerberos 5+2

Adam Mariš

·

Published

2017-11-08

·

Updated

2021-01-26

·

CVE-2017-15088

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (aka krb5) versions 1.15.2 and earlier
Description The issue concerns the mishandling of Distinguished Name (DN) fields in untrusted X.509 data, which can lead to the execution of arbitrary code or cause a denial of service due to a buffer overflow and application crash. This is related to the get matching data and X509 NAME oneline ex functions. The security relevance of this issue is primarily outside of the MIT Kerberos distribution, such as in the use of get matching data in KDC certauth plugin code specific to Red Hat.
Recommendations For versions 1.15.2 and earlier, update to a version later than 1.15.2 to resolve the issue.

Fix

RCE

DoS

Buffer Overflow

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1070
CVE-2017-15088
MGASA-2017-0420
OPENSUSE-SU-2017_2993-1
SUSE-SU-2017:2948-1
SUSE-SU-2017_2948-1

Affected Products

Alt Linux
Mit Kerberos 5
Suse