Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2695

Опубликовано: 14 сент. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.

A resource-access flaw was discovered in krb5; the SPNEGO mechanism operates under an incorrect assumption when dealing with its context handles. If an application calls gss_inquire_context() on a partially-established SPNEGO context, an unauthenticated, remote attacker could possibly exploit this flaw by sending a specially crafted SPNEGO packet and crashing the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4krb5Will not fix
Red Hat Enterprise Linux 5krb5Will not fix
Red Hat Enterprise Linux 6krb5Will not fix
Red Hat Enterprise Linux 7krb5Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=1275871krb5: SPNEGO context aliasing bugs

EPSS

Процентиль: 91%
0.06447
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.

nvd
около 10 лет назад

lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.

debian
около 10 лет назад

lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1. ...

suse-cvrf
около 10 лет назад

Security update for krb5

suse-cvrf
больше 10 лет назад

Security update for krb5

EPSS

Процентиль: 91%
0.06447
Низкий

4.3 Medium

CVSS2