PT-2023-8967 · Mit+9 · Mit Kerberos 5+9
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
MIT Kerberos 5 (aka krb5) versions 1.20.2 and earlier, 1.21.x versions prior to 1.21.1
Description
The issue is related to the lib/kadm5/kadm rpc xdr.c file in the Kerberos implementation, where an uninitialized pointer is freed. This can be exploited by a remote authenticated user to trigger a kadmind crash due to the lack of validation between
n key data and the key data array count in the xdr kadm5 principal ent rec function.Recommendations
For MIT Kerberos 5 (aka krb5) versions 1.20.2 and earlier, update to version 1.20.2 or later.
For MIT Kerberos 5 (aka krb5) 1.21.x versions prior to 1.21.1, update to version 1.21.1 or later.
As a temporary workaround, consider restricting access to the vulnerable
lib/kadm5/kadm rpc xdr.c module to minimize the risk of exploitation.Exploit
Fix
DoS
Access of Uninitialized Pointer
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Linuxmint
Mit Kerberos 5
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu