The process_as_req function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.10.x before 1.10.3 does not initialize a certain structure member, which allows remote attackers to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a malformed AS-REQ request.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade krb5 | Jul 30, 2024 | Aug 6, 2012 |
| Gentoo Linux | — | Upgrade app-crypt/mit-krb5. | Oct 30, 2017 | Aug 6, 2012 |
| Oracle Solaris | — | Upgrade consolidation/osnet/osnet-incorporation to version 0.5.11-0.175.2.0.0.42.2 on Solaris 11.2Upgrade system/security/kerberos-5 to version 0.5.11-0.175.1.7.0.3.2 on Solaris 11.1 | May 29, 2017 | Aug 6, 2012 |
| Suse | — | Upgrade krb5-serverUpgrade krb5-debuginfo-x86Upgrade krb5-client-debuginfoUpgrade krb5Upgrade krb5-plugin-kdb-ldapUpgrade krb5-debuginfo-32bitUpgrade krb5-server-debuginfoUpgrade krb5-debuginfoUpgrade krb5-x86Upgrade krb5-devel-32bitUpgrade krb5-plugin-kdb-ldap-debuginfoUpgrade krb5-clientUpgrade krb5-debugsourceUpgrade krb5-plugin-preauth-pkinitUpgrade krb5-plugin-preauth-pkinit-debuginfoUpgrade krb5-32bitUpgrade krb5-devel | Dec 12, 2013 | Aug 6, 2012 |
| Ubuntu | — | Upgrade krb5-admin-serverUpgrade krb5-kdc-ldapUpgrade krb5-kdc | Nov 8, 2024 | Aug 6, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub