Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-42898

Опубликовано: 25 дек. 2022
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*
Версия от 1.8 (включая) до 1.19.4 (исключая)
cpe:2.3:a:mit:kerberos_5:1.20:-:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.20:beta1:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:heimdal_project:heimdal:*:*:*:*:*:*:*:*
Версия до 7.7.1 (исключая)
Конфигурация 3

Одно из

cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
Версия до 4.15.12 (исключая)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
Версия от 4.16.0 (включая) до 4.16.7 (исключая)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
Версия от 4.17.0 (включая) до 4.17.3 (исключая)

EPSS

Процентиль: 91%
0.06859
Низкий

8.8 High

CVSS3

Дефекты

CWE-190
CWE-190

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 2 лет назад

PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

CVSS3: 8.8
redhat
больше 2 лет назад

PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

CVSS3: 8.8
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 8.8
debian
больше 2 лет назад

PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x befo ...

suse-cvrf
больше 2 лет назад

Security update for krb5

EPSS

Процентиль: 91%
0.06859
Низкий

8.8 High

CVSS3

Дефекты

CWE-190
CWE-190