ALT-PU-2018-1760-1
Closed vulnerabilities
Modified: 2025-04-12
CVE-2014-5355
MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a '\0' character, which allows remote attackers to (1) cause a denial of service (NULL pointer dereference) via a zero-byte version string or (2) cause a denial of service (out-of-bounds read) by omitting the '\0' character, related to appl/user_user/server.c and lib/krb5/krb/recvauth.c.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8050
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00061.html
- http://rhn.redhat.com/errata/RHSA-2015-0794.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:069
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/74042
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/102bb6ebf20f9174130c85c3b052ae104e5073ec
- https://lists.debian.org/debian-lts-announce/2018/01/msg00040.html
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8050
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00061.html
- http://rhn.redhat.com/errata/RHSA-2015-0794.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:069
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/74042
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/102bb6ebf20f9174130c85c3b052ae104e5073ec
- https://lists.debian.org/debian-lts-announce/2018/01/msg00040.html
Modified: 2025-04-12
CVE-2015-2694
The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1) zero bytes of data or (2) an arbitrary realm name, related to plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit_srv.c.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8160
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/74824
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/e3b5a5e5267818c97750b266df50b6a3d4649604
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8160
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/74824
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/e3b5a5e5267818c97750b266df50b6a3d4649604
Modified: 2025-04-12
CVE-2015-2695
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8244
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.html
- http://www.debian.org/security/2015/dsa-3395
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/90687
- http://www.securitytracker.com/id/1034084
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/b51b33f2bc5d1497ddf5bd107f791c101695000d
- https://security.gentoo.org/glsa/201611-14
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8244
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.html
- http://www.debian.org/security/2015/dsa-3395
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/90687
- http://www.securitytracker.com/id/1034084
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/b51b33f2bc5d1497ddf5bd107f791c101695000d
- https://security.gentoo.org/glsa/201611-14
Modified: 2025-04-12
CVE-2015-2696
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gss_inquire_context call.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8244
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.html
- http://www.debian.org/security/2015/dsa-3395
- http://www.securityfocus.com/bid/90675
- http://www.securitytracker.com/id/1034084
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/e04f0283516e80d2f93366e0d479d13c9b5c8c2a
- https://security.gentoo.org/glsa/201611-14
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8244
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.html
- http://www.debian.org/security/2015/dsa-3395
- http://www.securityfocus.com/bid/90675
- http://www.securitytracker.com/id/1034084
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/e04f0283516e80d2f93366e0d479d13c9b5c8c2a
- https://security.gentoo.org/glsa/201611-14
Modified: 2025-04-12
CVE-2015-2697
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8252
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.html
- http://www.debian.org/security/2015/dsa-3395
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/77581
- http://www.securitytracker.com/id/1034084
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/f0c094a1b745d91ef2f9a4eae2149aac026a5789
- https://security.gentoo.org/glsa/201611-14
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8252
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.html
- http://www.debian.org/security/2015/dsa-3395
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/77581
- http://www.securitytracker.com/id/1034084
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/f0c094a1b745d91ef2f9a4eae2149aac026a5789
- https://security.gentoo.org/glsa/201611-14
Modified: 2025-04-12
CVE-2015-2698
The iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly accesses a certain pointer, which allows remote authenticated users to cause a denial of service (memory corruption) or possibly have unspecified other impact by interacting with an application that calls the gss_export_sec_context function. NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-2696.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8273
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00116.html
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00124.html
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/3db8dfec1ef50ddd78d6ba9503185995876a39fd
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8273
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00116.html
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00124.html
- http://www.ubuntu.com/usn/USN-2810-1
- https://github.com/krb5/krb5/commit/3db8dfec1ef50ddd78d6ba9503185995876a39fd
Modified: 2025-04-12
CVE-2015-8629
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8341
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00110.html
- http://rhn.redhat.com/errata/RHSA-2016-0493.html
- http://rhn.redhat.com/errata/RHSA-2016-0532.html
- http://www.debian.org/security/2016/dsa-3466
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securityfocus.com/bid/82801
- http://www.securitytracker.com/id/1034914
- https://github.com/krb5/krb5/commit/df17a1224a3406f57477bcd372c61e04c0e5a5bb
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8341
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00110.html
- http://rhn.redhat.com/errata/RHSA-2016-0493.html
- http://rhn.redhat.com/errata/RHSA-2016-0532.html
- http://www.debian.org/security/2016/dsa-3466
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securityfocus.com/bid/82801
- http://www.securitytracker.com/id/1034914
- https://github.com/krb5/krb5/commit/df17a1224a3406f57477bcd372c61e04c0e5a5bb
Modified: 2025-04-12
CVE-2015-8630
The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by specifying KADM5_POLICY with a NULL policy name.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8342
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00110.html
- http://rhn.redhat.com/errata/RHSA-2016-0532.html
- http://www.debian.org/security/2016/dsa-3466
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securitytracker.com/id/1034915
- https://github.com/krb5/krb5/commit/b863de7fbf080b15e347a736fdda0a82d42f4f6b
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8342
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00110.html
- http://rhn.redhat.com/errata/RHSA-2016-0532.html
- http://www.debian.org/security/2016/dsa-3466
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securitytracker.com/id/1034915
- https://github.com/krb5/krb5/commit/b863de7fbf080b15e347a736fdda0a82d42f4f6b
Modified: 2025-04-12
CVE-2015-8631
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8343
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00110.html
- http://rhn.redhat.com/errata/RHSA-2016-0493.html
- http://rhn.redhat.com/errata/RHSA-2016-0532.html
- http://www.debian.org/security/2016/dsa-3466
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securitytracker.com/id/1034916
- https://github.com/krb5/krb5/commit/83ed75feba32e46f736fcce0d96a0445f29b96c2
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8343
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00110.html
- http://rhn.redhat.com/errata/RHSA-2016-0493.html
- http://rhn.redhat.com/errata/RHSA-2016-0532.html
- http://www.debian.org/security/2016/dsa-3466
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securitytracker.com/id/1034916
- https://github.com/krb5/krb5/commit/83ed75feba32e46f736fcce0d96a0445f29b96c2
Modified: 2025-04-12
CVE-2016-3119
The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00007.html
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00055.html
- http://rhn.redhat.com/errata/RHSA-2016-2591.html
- http://www.securityfocus.com/bid/85392
- http://www.securitytracker.com/id/1035399
- https://github.com/krb5/krb5/commit/08c642c09c38a9c6454ab43a9b53b2a89b9eef99
- https://lists.debian.org/debian-lts-announce/2018/01/msg00040.html
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00007.html
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00055.html
- http://rhn.redhat.com/errata/RHSA-2016-2591.html
- http://www.securityfocus.com/bid/85392
- http://www.securitytracker.com/id/1035399
- https://github.com/krb5/krb5/commit/08c642c09c38a9c6454ab43a9b53b2a89b9eef99
- https://lists.debian.org/debian-lts-announce/2018/01/msg00040.html
Modified: 2025-04-12
CVE-2016-3120
The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client data structure, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an S4U2Self request.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8458
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00035.html
- http://rhn.redhat.com/errata/RHSA-2016-2591.html
- http://web.mit.edu/kerberos/krb5-1.13/
- http://web.mit.edu/kerberos/krb5-1.14/
- http://www.securityfocus.com/bid/92132
- http://www.securitytracker.com/id/1036442
- https://github.com/krb5/krb5/commit/93b4a6306a0026cf1cc31ac4bd8a49ba5d034ba7
- https://lists.debian.org/debian-lts-announce/2018/01/msg00040.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AWL3KYFRJIX37EAM4DKCQQIQP2WBKL35/
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8458
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00035.html
- http://rhn.redhat.com/errata/RHSA-2016-2591.html
- http://web.mit.edu/kerberos/krb5-1.13/
- http://web.mit.edu/kerberos/krb5-1.14/
- http://www.securityfocus.com/bid/92132
- http://www.securitytracker.com/id/1036442
- https://github.com/krb5/krb5/commit/93b4a6306a0026cf1cc31ac4bd8a49ba5d034ba7
- https://lists.debian.org/debian-lts-announce/2018/01/msg00040.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AWL3KYFRJIX37EAM4DKCQQIQP2WBKL35/
Modified: 2025-04-20
CVE-2017-11368
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
- http://www.securityfocus.com/bid/100291
- https://access.redhat.com/errata/RHSA-2018:0666
- https://github.com/krb5/krb5/commit/ffb35baac6981f9e8914f8f3bffd37f284b85970
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4HNWXM6OQU7G23MG7XWIOBRGP43ECLDT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UBUTXMNZWMVJLQ4NDX5OQFPUVCJRLV3W/
- http://www.securityfocus.com/bid/100291
- https://access.redhat.com/errata/RHSA-2018:0666
- https://github.com/krb5/krb5/commit/ffb35baac6981f9e8914f8f3bffd37f284b85970
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4HNWXM6OQU7G23MG7XWIOBRGP43ECLDT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UBUTXMNZWMVJLQ4NDX5OQFPUVCJRLV3W/
Modified: 2025-04-20
CVE-2017-11462
Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8598
- https://bugzilla.redhat.com/show_bug.cgi?id=1488873
- https://github.com/krb5/krb5/commit/56f7b1bc95a2a3eeb420e069e7655fb181ade5cf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2FPRUP4YVOEBGEROUYWZFEQ64HTMGNED/
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8598
- https://bugzilla.redhat.com/show_bug.cgi?id=1488873
- https://github.com/krb5/krb5/commit/56f7b1bc95a2a3eeb420e069e7655fb181ade5cf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2FPRUP4YVOEBGEROUYWZFEQ64HTMGNED/