krb5: NULL pointer dereference (DoS, KDC crash) by processing certain TGS requests
Published Apr 19, 2013
4.0
MEDIUMCVSS 2.0
EPSS 2.92%
Description
The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS-REQ request.
Affected products
No data.
Configuration 1
- < 1.10.5
Configuration 2
Configuration 3
- 17
- 18
Configuration 4
- 6.0
- 6.4
- 6.0
- 6.4
- 6.0
No data.
Red Hat Enterprise Linux 6
krb5-0:1.10.3-10.el6_4.2
Fixed · RHSA-2013:0748
Red Hat Enterprise Linux 4
krb5
Not affected
Red Hat Enterprise Linux 5
krb5
Not affected
Red Hat JBoss Enterprise Web Server 2
krb5
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | krb5-0:1.10.3-10.el6_4.2 | Fixed | RHSA-2013:0748 |
| Red Hat Enterprise Linux 4 | krb5 | Not affected | n/a |
| Red Hat Enterprise Linux 5 | krb5 | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | krb5 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of krb5 as shipped with Red Hat Enterprise Linux 4 and 5.
References (15)
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=7600 x_refsource_CONFIRMVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102058.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102074.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-05/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00041.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00102.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0748.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:157 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:158 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-1416 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=949984 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-1454 Advisory
- https://github.com/krb5/krb5/commit/8ee70ec63931d1e38567905387ab9b1d45734d81 x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-1416
- https://www.cve.org/CVERecord?id=CVE-2013-1416
Change history (0)
No recorded changes yet.