CVE-2015-2697
published 2015-11-09CVE-2015-2697: The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of…
PriorityP419medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
4.13%
89.8th percentile
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | krb5 | < krb5 1.13.2+dfsg-3 (bookworm) | krb5 1.13.2+dfsg-3 (bookworm) |
| mit | kerberos_5 | < 1.14 | 1.14 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-3 | 1.13.2+dfsg-3 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-3 | 1.13.2+dfsg-3 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-3 | 1.13.2+dfsg-3 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-3 | 1.13.2+dfsg-3 |
| mit | krb5 | >= 0 < 1.12+dfsg-2ubuntu5.2 | 1.12+dfsg-2ubuntu5.2 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rw46-7hq3-wqv6: The build_principal_va function in lib/krb5/krb/bld_princ
ghsa_unreviewed·2022-05-13
CVE-2015-2697 [MEDIUM] CWE-125 GHSA-rw46-7hq3-wqv6: The build_principal_va function in lib/krb5/krb/bld_princ
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
OSV
krb5 vulnerabilities
osv·2015-11-12·CVSS 5.0
CVE-2002-2443 [MEDIUM] krb5 vulnerabilities
krb5 vulnerabilities
It was discovered that the Kerberos kpasswd service incorrectly handled
certain UDP packets. A remote attacker could possibly use this issue to
cause resource consumption, resulting in a denial of service. This issue
only affected Ubuntu 12.04 LTS. (CVE-2002-2443)
It was discovered that Kerberos incorrectly handled null bytes in certain
data fields. A remote attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-5355)
It was discovered that the Kerberos kdcpreauth modules incorrectly tracked
certain client requests. A remote attacker could possibly use this issue
to bypass intended preauthentication requirements. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-20
OSV
CVE-2015-2697: The build_principal_va function in lib/krb5/krb/bld_princ
osv·2015-11-09·CVSS 4.0
CVE-2015-2697 [MEDIUM] CVE-2015-2697: The build_principal_va function in lib/krb5/krb/bld_princ
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
Ubuntu
Kerberos vulnerabilities
vendor_ubuntu·2015-11-12·CVSS 5.0
CVE-2002-2443 [MEDIUM] Kerberos vulnerabilities
Title: Kerberos vulnerabilities
Summary: Several security issues were fixed in Kerberos.
It was discovered that the Kerberos kpasswd service incorrectly handled
certain UDP packets. A remote attacker could possibly use this issue to
cause resource consumption, resulting in a denial of service. This issue
only affected Ubuntu 12.04 LTS. (CVE-2002-2443)
It was discovered that Kerberos incorrectly handled null bytes in certain
data fields. A remote attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-5355)
It was discovered that the Kerberos kdcpreauth modules incorrectly tracked
certain client requests. A remote attacker could possibly use this issue
to bypass intended preauthentication requirements
Red Hat
krb5: build_principal() memory flaw
vendor_redhat·2015-09-25·CVSS 4.0
CVE-2015-2697 [MEDIUM] CWE-125 krb5: build_principal() memory flaw
krb5: build_principal() memory flaw
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
An out-of-bounds flaw was discovered in MIT Kerberos; the build_principal_va() function did not properly duplicate the realm. An authenticated remote attacker could possibly exploit this flaw by sending a TGS request containing a specially crafted realm field and crashing the KDC (denial of service).
Package: krb5 (Red Hat Enterprise Linux 4) - Not affected
Package: krb5 (Red Hat Enterprise Linux 5) - Not affected
Package: krb5 (Red Hat Enterprise Linux 6) - Will not fix
Package:
Debian
CVE-2015-2697: krb5 - The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (a...
vendor_debian·2015·CVSS 4.0
CVE-2015-2697 [MEDIUM] CVE-2015-2697: krb5 - The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (a...
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
Scope: local
bookworm: resolved (fixed in 1.13.2+dfsg-3)
bullseye: resolved (fixed in 1.13.2+dfsg-3)
forky: resolved (fixed in 1.13.2+dfsg-3)
sid: resolved (fixed in 1.13.2+dfsg-3)
trixie: resolved (fixed in 1.13.2+dfsg-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2697 CVE-2015-2696 CVE-2015-2695 krb5: various flaws [fedora-all]
bugzilla·2015-10-28·CVSS 5.0
CVE-2015-2697 [MEDIUM] CVE-2015-2697 CVE-2015-2696 CVE-2015-2695 krb5: various flaws [fedora-all]
CVE-2015-2697 CVE-2015-2696 CVE-2015-2695 krb5: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2015-2697 krb5: build_principal() memory flaw
bugzilla·2015-10-28·CVSS 4.0
CVE-2015-2697 [MEDIUM] CVE-2015-2697 krb5: build_principal() memory flaw
CVE-2015-2697 krb5: build_principal() memory flaw
The kerberos project reports:
In build_principal_va(), use k5memdup0() instead of strdup() to make a
copy of the realm, to ensure that we allocate the correct number of
bytes and do not read past the end of the input string. This bug
affects krb5_build_principal(), krb5_build_principal_va(), and
krb5_build_principal_alloc_va(). krb5_build_principal_ext() is not
affected.
CVE-2015-2697:
In MIT krb5 1.7 and later, an authenticated attacker may be able to
cause a KDC to crash using a TGS request with a large realm field
beginning with a null byte. If the KDC attempts to find a referral to
answer the request, it constructs a principal name for lookup using
krb5_build_principal() with the requested realm. Due to a bug in this
function, the n
http://krbdev.mit.edu/rt/Ticket/Display.html?id=8252http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.htmlhttp://www.debian.org/security/2015/dsa-3395http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/77581http://www.securitytracker.com/id/1034084http://www.ubuntu.com/usn/USN-2810-1https://github.com/krb5/krb5/commit/f0c094a1b745d91ef2f9a4eae2149aac026a5789https://security.gentoo.org/glsa/201611-14http://krbdev.mit.edu/rt/Ticket/Display.html?id=8252http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.htmlhttp://www.debian.org/security/2015/dsa-3395http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/77581http://www.securitytracker.com/id/1034084http://www.ubuntu.com/usn/USN-2810-1https://github.com/krb5/krb5/commit/f0c094a1b745d91ef2f9a4eae2149aac026a5789https://security.gentoo.org/glsa/201611-14
2015-11-09
Published