UBUNTU-CVE-2013-1417
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 20 Nov 2013, 14:12
Last modified:16 Jul 2025, 07:31
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
20 Nov 2013, 14:12
Published
Vulnerability first disclosed
16 Jul 2025, 07:31
Last Modified
Vulnerability information updated
Description
do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.11 before 1.11.4, when a single-component realm name is used, allows remote authenticated users to cause a denial of service (daemon crash) via a TGS-REQ request that triggers an attempted cross-realm referral for a host-based service principal.
Affected Systems
- ubuntu•krb5
< 1.12+dfsg-2ubuntu4