The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the db2 (aka Berkeley DB) or LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger certain process_as_req errors.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade krb5 | Jul 30, 2024 | Oct 20, 2011 |
| Gentoo Linux | — | Upgrade app-crypt/mit-krb5. | Oct 30, 2017 | Oct 20, 2011 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.1.0.0.24.2 on Solaris 11.1 | May 29, 2017 | Oct 20, 2011 |
| Oracle_linux | — | Upgrade krb5-workstationUpgrade krb5-develUpgrade krb5-serverUpgrade krb5-pkinit-opensslUpgrade krb5-libsUpgrade krb5-server-ldap | Oct 16, 2024 | Oct 20, 2011 |
| Suse | — | Upgrade krb5-docUpgrade krb5-plugin-preauth-pkinitUpgrade krb5-serverUpgrade krb5-develUpgrade krb5Upgrade krb5-32bitUpgrade krb5-clientUpgrade krb5-plugin-preauth-otpUpgrade krb5-plugin-preauth-spakeUpgrade krb5-plugin-kdb-ldap | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade krb5-kdcUpgrade krb5-kdc-ldap | Nov 8, 2024 | Oct 20, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub