CVE-2015-2695
published 2015-11-09CVE-2015-2695: lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.24%
92.8th percentile
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | krb5 | < krb5 1.13.2+dfsg-3 (bookworm) | krb5 1.13.2+dfsg-3 (bookworm) |
| mit | kerberos_5 | < 1.14 | 1.14 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-3 | 1.13.2+dfsg-3 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-3 | 1.13.2+dfsg-3 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-3 | 1.13.2+dfsg-3 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-3 | 1.13.2+dfsg-3 |
| mit | krb5 | >= 0 < 1.12+dfsg-2ubuntu5.2 | 1.12+dfsg-2ubuntu5.2 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Kerberos vulnerabilities
vendor_ubuntu·2015-11-12·CVSS 5.0
CVE-2002-2443 [MEDIUM] Kerberos vulnerabilities
Title: Kerberos vulnerabilities
Summary: Several security issues were fixed in Kerberos.
It was discovered that the Kerberos kpasswd service incorrectly handled
certain UDP packets. A remote attacker could possibly use this issue to
cause resource consumption, resulting in a denial of service. This issue
only affected Ubuntu 12.04 LTS. (CVE-2002-2443)
It was discovered that Kerberos incorrectly handled null bytes in certain
data fields. A remote attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-5355)
It was discovered that the Kerberos kdcpreauth modules incorrectly tracked
certain client requests. A remote attacker could possibly use this issue
to bypass intended preauthentication requirements
Red Hat
krb5: SPNEGO context aliasing bugs
vendor_redhat·2015-09-14·CVSS 5.0
CVE-2015-2695 [MEDIUM] CWE-843 krb5: SPNEGO context aliasing bugs
krb5: SPNEGO context aliasing bugs
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
A resource-access flaw was discovered in krb5; the SPNEGO mechanism operates under an incorrect assumption when dealing with its context handles. If an application calls gss_inquire_context() on a partially-established SPNEGO context, an unauthenticated, remote attacker could possibly exploit this flaw by sending a specially crafted SPNEGO packet and crashing the system.
Package: krb5 (Red Hat Enterprise Linux 4) - Will not fix
Package: krb5 (Red Hat Enterp
Debian
CVE-2015-2695: krb5 - lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies ...
vendor_debian·2015·CVSS 5.0
CVE-2015-2695 [MEDIUM] CVE-2015-2695: krb5 - lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies ...
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
Scope: local
bookworm: resolved (fixed in 1.13.2+dfsg-3)
bullseye: resolved (fixed in 1.13.2+dfsg-3)
forky: resolved (fixed in 1.13.2+dfsg-3)
sid: resolved (fixed in 1.13.2+dfsg-3)
trixie: resolved (fixed in 1.13.2+dfsg-3)
GHSA
GHSA-px5h-p825-xfmc: lib/gssapi/spnego/spnego_mech
ghsa_unreviewed·2022-05-13
CVE-2015-2695 [MEDIUM] CWE-763 GHSA-px5h-p825-xfmc: lib/gssapi/spnego/spnego_mech
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
OSV
krb5 vulnerabilities
osv·2015-11-12·CVSS 5.0
CVE-2002-2443 [MEDIUM] krb5 vulnerabilities
krb5 vulnerabilities
It was discovered that the Kerberos kpasswd service incorrectly handled
certain UDP packets. A remote attacker could possibly use this issue to
cause resource consumption, resulting in a denial of service. This issue
only affected Ubuntu 12.04 LTS. (CVE-2002-2443)
It was discovered that Kerberos incorrectly handled null bytes in certain
data fields. A remote attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-5355)
It was discovered that the Kerberos kdcpreauth modules incorrectly tracked
certain client requests. A remote attacker could possibly use this issue
to bypass intended preauthentication requirements. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-20
OSV
CVE-2015-2695: lib/gssapi/spnego/spnego_mech
osv·2015-11-09·CVSS 5.0
CVE-2015-2695 [MEDIUM] CVE-2015-2695: lib/gssapi/spnego/spnego_mech
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2695 krb5: SPNEGO context aliasing bugs
bugzilla·2015-10-28·CVSS 5.0
CVE-2015-2695 [MEDIUM] CVE-2015-2695 krb5: SPNEGO context aliasing bugs
CVE-2015-2695 krb5: SPNEGO context aliasing bugs
The kerberos project reports:
The SPNEGO mechanism currently replaces its context handle with the
mechanism context handle upon establishment, under the assumption that
most GSS functions are only called after context establishment. This
assumption is incorrect, and can lead to aliasing violations for some
programs. Maintain the SPNEGO context structure after context
establishment and refer to it in all GSS methods. Add initiate and
opened flags to the SPNEGO context structure for use in
gss_inquire_context() prior to context establishment.
CVE-2015-2695:
In MIT krb5 1.5 and later, applications which call
gss_inquire_context() on a partially-established SPNEGO context can
cause the GSS-API library to read from a pointer using the wrong t
Bugzilla
CVE-2015-2697 CVE-2015-2696 CVE-2015-2695 krb5: various flaws [fedora-all]
bugzilla·2015-10-28·CVSS 5.0
CVE-2015-2697 [MEDIUM] CVE-2015-2697 CVE-2015-2696 CVE-2015-2695 krb5: various flaws [fedora-all]
CVE-2015-2697 CVE-2015-2696 CVE-2015-2695 krb5: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
http://krbdev.mit.edu/rt/Ticket/Display.html?id=8244http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.htmlhttp://www.debian.org/security/2015/dsa-3395http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/90687http://www.securitytracker.com/id/1034084http://www.ubuntu.com/usn/USN-2810-1https://github.com/krb5/krb5/commit/b51b33f2bc5d1497ddf5bd107f791c101695000dhttps://security.gentoo.org/glsa/201611-14http://krbdev.mit.edu/rt/Ticket/Display.html?id=8244http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.htmlhttp://www.debian.org/security/2015/dsa-3395http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/90687http://www.securitytracker.com/id/1034084http://www.ubuntu.com/usn/USN-2810-1https://github.com/krb5/krb5/commit/b51b33f2bc5d1497ddf5bd107f791c101695000dhttps://security.gentoo.org/glsa/201611-14
2015-11-09
Published