Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-3120

Опубликовано: 01 авг. 2016
Источник: ubuntu
Приоритет: medium
CVSS2: 4
CVSS3: 6.5

Описание

The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client data structure, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an S4U2Self request.

РелизСтатусПримечание
artful

not-affected

1.14.3+dfsg-2ubuntu1
bionic

not-affected

1.14.3+dfsg-2ubuntu1
cosmic

not-affected

1.14.3+dfsg-2ubuntu1
devel

not-affected

1.14.3+dfsg-2ubuntu1
disco

not-affected

1.14.3+dfsg-2ubuntu1
eoan

not-affected

1.14.3+dfsg-2ubuntu1
esm-infra-legacy/trusty

released

1.12+dfsg-2ubuntu5.4
esm-infra/bionic

not-affected

1.14.3+dfsg-2ubuntu1
esm-infra/focal

not-affected

1.14.3+dfsg-2ubuntu1
esm-infra/xenial

released

1.13.2+dfsg-5ubuntu2.1

Показывать по

Ссылки на источники

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
около 9 лет назад

The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client data structure, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an S4U2Self request.

CVSS3: 6.5
nvd
около 9 лет назад

The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client data structure, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an S4U2Self request.

CVSS3: 6.5
debian
около 9 лет назад

The validate_as_request function in kdc_util.c in the Key Distribution ...

suse-cvrf
около 9 лет назад

Security update for krb5

suse-cvrf
около 9 лет назад

Security update for krb5

4 Medium

CVSS2

6.5 Medium

CVSS3