CVE-2013-1416
Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 19 Apr 2013, 10:00
Last modified:06 Aug 2024, 15:04
Vulnerability Summary
Overall Risk (default)
low
16/100 CVSS Score
4 MEDIUM
v2.0 (nvd)
EPSS Score
2.27% LOW
2% probability -0.36%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
19 Apr 2013, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 15:04
Last Modified
Vulnerability information updated
Description
The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS-REQ request.
CVSS Metrics
- v2.0•MEDIUM•Score: 4AV:N/AC:L/Au:S/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 2.27%• Percentile: 85%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- fedoraproject•fedora
17 | 18
- mit•kerberos_5
< 1.10.5
- opensuse•opensuse
11.4 | 12.1 | 12.2 | 12.3
- redhat•enterprise_linux_desktop
6.0
- redhat•enterprise_linux_eus
6.4
- redhat•enterprise_linux_server
6.0
- redhat•enterprise_linux_server_aus
6.4
- redhat•enterprise_linux_workstation
6.0
References (10)
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:157
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00041.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:158
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102074.html
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00102.html
- http://lists.opensuse.org/opensuse-updates/2013-05/msg00011.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102058.html
- https://github.com/krb5/krb5/commit/8ee70ec63931d1e38567905387ab9b1d45734d81
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=7600
- http://rhn.redhat.com/errata/RHSA-2013-0748.html