Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14844

Опубликовано: 26 сент. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.

A flaw was found in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.

Отчет

This flaw affects the krb5 server only; client-side packages are not affected. This flaw does not affect any krb5 packages shipped with Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5krb5Not affected
Red Hat Enterprise Linux 6krb5Not affected
Red Hat Enterprise Linux 7krb5Not affected
Red Hat Enterprise Linux 8krb5Not affected
Red Hat JBoss Core Serviceskrb5Not affected
Red Hat JBoss Enterprise Web Server 2krb5Not affected
Red Hat Virtualization 4redhat-virtualization-hostNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-628
https://bugzilla.redhat.com/show_bug.cgi?id=1753589krb5: reversed strlcpy() allows client to crash the KDC

EPSS

Процентиль: 90%
0.04436
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.

CVSS3: 7.5
nvd
почти 7 лет назад

A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.

CVSS3: 7.5
msrc
почти 5 лет назад

A flaw was found in Fedora versions of krb5 from 1.16.1 to including 1.17.x in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.

CVSS3: 7.5
debian
почти 7 лет назад

A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including ...

CVSS3: 7.5
github
около 4 лет назад

A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.

EPSS

Процентиль: 90%
0.04436
Низкий

7.5 High

CVSS3