Описание
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
A vulnerability was found in MIT krb5. This flaw allows an authenticated attacker to cause a KDC or kadmind process to crash by reading beyond the bounds of allocated memory, creating a denial of service. A privileged attacker may similarly be able to cause a Kerberos or GSS application service to crash.
Отчет
Samba in RHEL does not implement the AD DC role and is not built against Heimdal, thus Samba is not affected by this CVE.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | samba | Not affected | ||
Red Hat Enterprise Linux 6 | samba4 | Not affected | ||
Red Hat Enterprise Linux 7 | samba | Not affected | ||
Red Hat Enterprise Linux 8 | samba | Not affected | ||
Red Hat Enterprise Linux 9 | samba | Not affected | ||
Red Hat Storage 3 | samba | Not affected | ||
Red Hat Enterprise Linux 6 Extended Lifecycle Support | krb5 | Fixed | RHSA-2022:8663 | 29.11.2022 |
Red Hat Enterprise Linux 7 | krb5 | Fixed | RHSA-2022:8640 | 28.11.2022 |
Red Hat Enterprise Linux 8 | krb5 | Fixed | RHEA-2023:3850 | 27.06.2023 |
Red Hat Enterprise Linux 8 | krb5 | Fixed | RHSA-2022:8638 | 28.11.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x befo ...
EPSS
8.8 High
CVSS3