PT-2021-3744 · Mit+11 · Mit Kerberos 5+10
Published
2021-07-22
·
Updated
2024-07-24
·
CVE-2021-36222
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
MIT Kerberos 5 (krb5) versions prior to 1.18.4
MIT Kerberos 5 (krb5) versions 1.19.x prior to 1.19.2
MySQL Server versions 8.0.26 and earlier
Description
The issue is related to a NULL pointer dereference in the Key Distribution Center (KDC) component of the Kerberos authentication protocol. This can be exploited by remote attackers to cause a daemon crash, resulting in a denial of service. The vulnerability is also present in the MySQL Server component, specifically in the Server:Compiling(Kerberos) subcomponent, allowing a high-privileged attacker with network access to compromise the MySQL Server, potentially causing a hang or crash.
Recommendations
For MIT Kerberos 5 (krb5) versions prior to 1.18.4, update to version 1.18.4 or later.
For MIT Kerberos 5 (krb5) versions 1.19.x prior to 1.19.2, update to version 1.19.2 or later.
For MySQL Server versions 8.0.26 and earlier, update to a version later than 8.0.26.
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Centos
Linuxmint
Mit Kerberos 5
Mysql Server
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu