CVE-2015-8631
published 2016-02-13CVE-2015-8631: Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated…
PriorityP430medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
4.64%
90.7th percentile
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | krb5 | < krb5 1.13.2+dfsg-5 (bookworm) | krb5 1.13.2+dfsg-5 (bookworm) |
| mit | kerberos_5 | < 1.13.4 | 1.13.4 |
| mit | kerberos_5 | >= 1.14 < 1.14.1 | 1.14.1 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-5 | 1.13.2+dfsg-5 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-5 | 1.13.2+dfsg-5 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-5 | 1.13.2+dfsg-5 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-5 | 1.13.2+dfsg-5 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7f2w-w6q2-vgj3: Multiple memory leaks in kadmin/server/server_stubs
ghsa_unreviewed·2022-05-13
CVE-2015-8631 [MEDIUM] CWE-772 GHSA-7f2w-w6q2-vgj3: Multiple memory leaks in kadmin/server/server_stubs
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
OSV
CVE-2015-8631: Multiple memory leaks in kadmin/server/server_stubs
osv·2016-02-13·CVSS 6.5
CVE-2015-8631 [MEDIUM] CVE-2015-8631: Multiple memory leaks in kadmin/server/server_stubs
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
Red Hat
krb5: Memory leak caused by supplying a null principal name in request
vendor_redhat·2016-01-08·CVSS 6.5
CVE-2015-8631 [MEDIUM] CWE-401 krb5: Memory leak caused by supplying a null principal name in request
krb5: Memory leak caused by supplying a null principal name in request
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
A memory leak flaw was found in the krb5_unparse_name() function of the MIT Kerberos kadmind service. An authenticated attacker could repeatedly send specially crafted requests to the server, which could cause the server to consume large amounts of memory resources, ultimately leading to a denial of service due to memory exhaustion.
Package: krb5 (Red Hat Enterprise Linux 5) - Will not fix
Package: krb5 (Red Hat JBoss Enterprise Web Server 2) - Not affected
Debian
CVE-2015-8631: krb5 - Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos...
vendor_debian·2015·CVSS 6.5
CVE-2015-8631 [MEDIUM] CVE-2015-8631: krb5 - Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos...
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
Scope: local
bookworm: resolved (fixed in 1.13.2+dfsg-5)
bullseye: resolved (fixed in 1.13.2+dfsg-5)
forky: resolved (fixed in 1.13.2+dfsg-5)
sid: resolved (fixed in 1.13.2+dfsg-5)
trixie: resolved (fixed in 1.13.2+dfsg-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8631 krb5: Memory leak caused by supplying a null principal name in request
bugzilla·2016-01-28·CVSS 6.5
CVE-2015-8631 [MEDIUM] CVE-2015-8631 krb5: Memory leak caused by supplying a null principal name in request
CVE-2015-8631 krb5: Memory leak caused by supplying a null principal name in request
It was reported that if krb5_unparse_name() fails, many of the stubs will leak the client and server name. In all versions of MIT krb5, an authenticated attacker can cause kadmind to leak memory by supplying a null principal name in a request which uses one. Repeating these requests will eventually cause kadmind to exhaust all available memory.
Upstream patch:
https://github.com/krb5/krb5/commit/83ed75feba32e46f736fcce0d96a0445f29b96c2
Discussion:
Created krb5 tracking bugs for this issue:
Affects: fedora-all [bug 1302643]
---
Acknowledgements:
This issue was discovered by Simo Sorce of Red Hat.
---
Upstream bug report:
http://krbdev.mit.edu/rt/Ticket/Display.html?id=8343
Fixed upstream in krb
Bugzilla
CVE-2015-8631 krb5: Memory leak caused by supplying a null principal name in request [fedora-all]
bugzilla·2016-01-28·CVSS 6.5
CVE-2015-8631 [MEDIUM] CVE-2015-8631 krb5: Memory leak caused by supplying a null principal name in request [fedora-all]
CVE-2015-8631 krb5: Memory leak caused by supplying a null principal name in request [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
http://krbdev.mit.edu/rt/Ticket/Display.html?id=8343http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00110.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0493.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0532.htmlhttp://www.debian.org/security/2016/dsa-3466http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securitytracker.com/id/1034916https://github.com/krb5/krb5/commit/83ed75feba32e46f736fcce0d96a0445f29b96c2http://krbdev.mit.edu/rt/Ticket/Display.html?id=8343http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00110.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0493.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0532.htmlhttp://www.debian.org/security/2016/dsa-3466http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securitytracker.com/id/1034916https://github.com/krb5/krb5/commit/83ed75feba32e46f736fcce0d96a0445f29b96c2
2016-02-13
Published