Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3206

Опубликовано: 25 авг. 2017
Источник: debian
EPSS Низкий

Описание

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pykerberosfixed1.1.5-1package
pykerberosfixed1.1.5-0.1+deb8u1jessiepackage
pykerberosfixed1.1+svn4895-1+deb7u1wheezypackage

Примечания

  • CVE originally assigned for python-kerberos, pykerberos is a fork of the

  • former.

  • KDC verification support in pykerberos added in https://github.com/02strich/pykerberos/commit/02d13860b25fab58e739f0e000bed0067b7c6f9c

  • Using the above code as is might break existing installations since a keytab is required to call krb5_verify_init_creds

EPSS

Процентиль: 76%
0.00963
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 8 лет назад

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

redhat
больше 10 лет назад

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

CVSS3: 8.1
nvd
больше 8 лет назад

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

CVSS3: 8.1
github
больше 3 лет назад

python-kerberos vulnerable to KDC spoofing attacks

EPSS

Процентиль: 76%
0.00963
Низкий