Mit

Kerberos 5

142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.13%
  • Veröffentlicht 09.11.2015 03:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field...

  • EPSS 4.54%
  • Veröffentlicht 09.11.2015 03:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mis...

  • EPSS 6.24%
  • Veröffentlicht 09.11.2015 03:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that...

  • EPSS 2.84%
  • Veröffentlicht 25.05.2015 19:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1...

  • EPSS 4.59%
  • Veröffentlicht 20.02.2015 11:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a '\0' character, which allows remote attackers to (1) cause a denial of service (NULL pointer dereference) via a ...

  • EPSS 3.89%
  • Veröffentlicht 19.02.2015 11:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attacker...

  • EPSS 2.73%
  • Veröffentlicht 19.02.2015 11:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 allows remote authenticated users to bypass a kadmin/* authorization check and obta...

  • EPSS 6.21%
  • Veröffentlicht 19.02.2015 11:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly handle partial XDR deserialization, which allows remote authenticated us...

  • EPSS 6.21%
  • Veröffentlicht 19.02.2015 11:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly maintain security-cont...

  • EPSS 1.74%
  • Veröffentlicht 16.12.2014 23:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by creatin...