Описание
The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1) zero bytes of data or (2) an arbitrary realm name, related to plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit_srv.c.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 1.13.2+dfsg-3 |
esm-infra-legacy/trusty | not-affected | 1.12+dfsg-2ubuntu5.2 |
lucid | not-affected | 1.8.1+dfsg-2ubuntu0.14 |
precise | not-affected | 1.10+dfsg~beta1-2ubuntu0.6 |
trusty | released | 1.12+dfsg-2ubuntu5.2 |
trusty/esm | not-affected | 1.12+dfsg-2ubuntu5.2 |
upstream | released | 1.13.2,1.12.1+dfsg-20 |
utopic | ignored | end of life |
vivid | released | 1.12.1+dfsg-18ubuntu0.1 |
vivid/stable-phone-overlay | released | 1.12.1+dfsg-18ubuntu0.1 |
Показывать по
EPSS
5.8 Medium
CVSS2
Связанные уязвимости
The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1) zero bytes of data or (2) an arbitrary realm name, related to plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit_srv.c.
The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1) zero bytes of data or (2) an arbitrary realm name, related to plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit_srv.c.
The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x ...
The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1) zero bytes of data or (2) an arbitrary realm name, related to plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit_srv.c.
ELSA-2015-2154: krb5 security, bug fix, and enhancement update (MODERATE)
EPSS
5.8 Medium
CVSS2