UBUNTU-CVE-2013-1417

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 20 Nov 2013, 14:12
Last modified:16 Jul 2025, 07:31

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Nov 2013, 14:12
Published
Vulnerability first disclosed
16 Jul 2025, 07:31
Last Modified
Vulnerability information updated

Description

do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.11 before 1.11.4, when a single-component realm name is used, allows remote authenticated users to cause a denial of service (daemon crash) via a TGS-REQ request that triggers an attempted cross-realm referral for a host-based service principal.

Affected Systems

  • ubuntukrb5

    < 1.12+dfsg-2ubuntu4

References (3)