DEBIAN-CVE-2013-1417
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 20 Nov 2013, 14:12
Last modified:28 Apr 2026, 20:12
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
20 Nov 2013, 14:12
Published
Vulnerability first disclosed
28 Apr 2026, 20:12
Last Modified
Vulnerability information updated
Description
do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.11 before 1.11.4, when a single-component realm name is used, allows remote authenticated users to cause a denial of service (daemon crash) via a TGS-REQ request that triggers an attempted cross-realm referral for a host-based service principal.
Affected Systems
- debian•krb5
< 1.11.3+dfsg-3+nmu1 | < 1.11.3+dfsg-3+nmu1 | < 1.11.3+dfsg-3+nmu1 | < 1.11.3+dfsg-3+nmu1