PT-2021-3744 · Mit+11 · Mit Kerberos 5+10

Published

2021-07-22

·

Updated

2024-07-24

·

CVE-2021-36222

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (krb5) versions prior to 1.18.4 MIT Kerberos 5 (krb5) versions 1.19.x prior to 1.19.2 MySQL Server versions 8.0.26 and earlier
Description The issue is related to a NULL pointer dereference in the Key Distribution Center (KDC) component of the Kerberos authentication protocol. This can be exploited by remote attackers to cause a daemon crash, resulting in a denial of service. The vulnerability is also present in the MySQL Server component, specifically in the Server:Compiling(Kerberos) subcomponent, allowing a high-privileged attacker with network access to compromise the MySQL Server, potentially causing a hang or crash.
Recommendations For MIT Kerberos 5 (krb5) versions prior to 1.18.4, update to version 1.18.4 or later. For MIT Kerberos 5 (krb5) versions 1.19.x prior to 1.19.2, update to version 1.19.2 or later. For MySQL Server versions 8.0.26 and earlier, update to a version later than 8.0.26.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2320
ALT-PU-2021-2324
ALT-PU-2021-2358
ALT-PU-2021-3124
ALT-PU-2021-3241
ALT-PU-2022-2171
ALT-PU-2023-1912
AZL-6607
BDU:2021-03997
CESA-2021_3576
CVE-2021-36222
DSA-4944-1
OESA-2021-1283
OPENSUSE-SU-2021:1182-1
OPENSUSE-SU-2021:2800-1
OPENSUSE-SU-2021_1182-1
OPENSUSE-SU-2021_2800-1
OPENSUSE-SU-2022:0283-1
OPENSUSE-SU-2022_0283-1
OPENSUSE-SU-2022_1396-1
OPENSUSE-SU-2022_4428-1
OPENSUSE-SU-2022_4437-1
OPENSUSE-SU-2024:10899-1
OPENSUSE-SU-2024:11816-1
RHSA-2021:3576
RHSA-2021_3576
RLSA-2021:3576
SUSE-FU-2022:1419-1
SUSE-SU-2021:2800-1
SUSE-SU-2021_2800-1
SUSE-SU-2022:0283-1
SUSE-SU-2022:0751-1
SUSE-SU-2022:1396-1
SUSE-SU-2022:2134-1
SUSE-SU-2022:3676-1
SUSE-SU-2022:4428-1
SUSE-SU-2022:4437-1
SUSE-SU-2022:4439-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1
USN-5959-1

Affected Products

Alt Linux
Astra Linux
Centos
Linuxmint
Mit Kerberos 5
Mysql Server
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu