CVE-2013-1416

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 19 Apr 2013, 10:00
Last modified:06 Aug 2024, 15:04

Vulnerability Summary

Overall Risk (default)
low
16/100
CVSS Score
4 MEDIUM
v2.0 (nvd)
EPSS Score
2.27% LOW
2% probability -0.36%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Apr 2013, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 15:04
Last Modified
Vulnerability information updated

Description

The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS-REQ request.

CVSS Metrics

  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 2.27% Percentile: 85%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • fedoraprojectfedora

    17 | 18

  • mitkerberos_5

    < 1.10.5

  • opensuseopensuse

    11.4 | 12.1 | 12.2 | 12.3

  • redhatenterprise_linux_desktop

    6.0

  • redhatenterprise_linux_eus

    6.4

  • redhatenterprise_linux_server

    6.0

  • redhatenterprise_linux_server_aus

    6.4

  • redhatenterprise_linux_workstation

    6.0

References (10)