The "mechglue" abstraction interface of the GSS-API library for Kerberos 5 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, allows remote attackers to cause a denial of service (crash) via unspecified vectors that cause mechglue to free uninitialized pointers.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade app-crypt/mit-krb5. | Oct 30, 2017 | Dec 31, 2006 |
| Suse | — | Upgrade krb5-serverUpgrade krb5-plugin-preauth-pkinitUpgrade krb5-32bitUpgrade krb5Upgrade krb5-devel-32bitUpgrade krb5-clientUpgrade krb5-plugin-preauth-spakeUpgrade krb5-plugin-kdb-ldapUpgrade krb5-apps-serversUpgrade krb5-apps-clientsUpgrade krb5-plugin-preauth-otpUpgrade krb5-x86Upgrade krb5-devel | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub