PT-2018-8407 · Mit+4 · Kerberos+4
Pedrohc
·
Published
2017-11-20
·
Updated
2023-02-12
·
CVE-2017-7562
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Kerberos versions prior to 1.16.1
Description
An authentication bypass flaw was found in the way krb5's certauth interface handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and erroneous circumstances.
Recommendations
For versions prior to 1.16.1, update to version 1.16.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the certauth interface until a patch is available.
Fix
Improper Certificate Validation
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Kerberos
Red Hat
Suse