CVE-2015-2696Type Confusion in Kerberos 5

Severity
7.1HIGHNVD
EPSS
8.3%
top 7.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9
Latest updateMay 13

Description

lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gss_inquire_context call.

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages7 packages

Debianmit/krb5< 1.13.2+dfsg-3+3
NVDmit/kerberos_5< 1.14
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 15.04, 15.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hr7f-g375-m62r: lib/gssapi/krb5/iakerb2022-05-13
OSV
CVE-2015-2696: lib/gssapi/krb5/iakerb2015-11-09
CVEList
CVE-2015-2696: lib/gssapi/krb5/iakerb2015-11-09

📋Vendor Advisories

4
Ubuntu
Kerberos vulnerabilities2015-11-12
Red Hat
krb5: IAKERB context export/import2015-11-01
Red Hat
krb5: IAKERB context aliasing flaw2015-09-14
Debian
CVE-2015-2696: krb5 - lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an i...2015

💬Community

3
Bugzilla
CVE-2015-2698 krb5: IAKERB context export/import2015-11-06
Bugzilla
CVE-2015-2697 CVE-2015-2696 CVE-2015-2695 krb5: various flaws [fedora-all]2015-10-28
Bugzilla
CVE-2015-2696 krb5: IAKERB context aliasing flaw2015-10-28
CVE-2015-2696 — Type Confusion in MIT Kerberos 5 | cvebase