5
CVE-2015-2695
- EPSS 6.24%
- Veröffentlicht 09.11.2015 03:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mit ≫ Kerberos 5 Version < 1.14
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 15.04
Canonical ≫ Ubuntu Linux Version 15.10
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Suse ≫ Linux Enterprise Desktop Version 11 Update sp3
Suse ≫ Linux Enterprise Desktop Version 11 Update sp4
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform vmware
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update -
Suse ≫ Linux Enterprise Software Development Kit Version 11 Update sp3
Suse ≫ Linux Enterprise Software Development Kit Version 11 Update sp4
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.24% | 0.926 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-763 Release of Invalid Pointer or Reference
The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.ubuntu.com/usn/USN-2810-1
http://krbdev.mit.edu/rt/Ticket/Display.html?id=8244
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.html
http://www.debian.org/security/2015/dsa-3395
http://www.securityfocus.com/bid/90687
http://www.securitytracker.com/id/1034084
https://github.com/krb5/krb5/commit/b51b33f2bc5d1497ddf5bd107f791c101695000d
https://security.gentoo.org/glsa/201611-14