CVE-2023-36054
published 2023-08-07CVE-2023-36054: lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.79%
84.8th percentile
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | krb5 | < krb5 1.20.1-2+deb12u1 (bookworm) | krb5 1.20.1-2+deb12u1 (bookworm) |
| mit | kerberos_5 | < 1.20.2 | 1.20.2 |
| mit | kerberos_5 | — | — |
| mit | krb5 | >= 0 < 1.18.3-6+deb11u4 | 1.18.3-6+deb11u4 |
| mit | krb5 | >= 0 < 1.20.1-2+deb12u1 | 1.20.1-2+deb12u1 |
| mit | krb5 | >= 0 < 1.20.1-3 | 1.20.1-3 |
| mit | krb5 | >= 0 < 1.20.1-3 | 1.20.1-3 |
| msrc | cbl2_krb5_1.19.4-2_on_cbl_mariner_2.0 | — | — |
| netapp | clustered_data_ontap | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
Kerberos vulnerability
vendor_ubuntu·2023-11-06
CVE-2023-36054 Kerberos vulnerability
Title: Kerberos vulnerability
Summary: Kerberos could be made to crash if it received specially crafted
network traffic.
USN-6467-1 fixed a vulnerability in Kerberos. This update provides the
corresponding update for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu
23.04.
Original advisory details:
Robert Morris discovered that Kerberos did not properly handle memory
access when processing RPC data through kadmind, which could lead to the
freeing of uninitialized memory. An authenticated remote attacker could
possibly use this issue to cause kadmind to crash, resulting in a denial
of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Kerberos vulnerability
vendor_ubuntu·2023-11-01
CVE-2023-36054 Kerberos vulnerability
Title: Kerberos vulnerability
Summary: Kerberos could be made to crash if it received specially crafted
network traffic.
Robert Morris discovered that Kerberos did not properly handle memory
access when processing RPC data through kadmind, which could lead to the
freeing of uninitialized memory. An authenticated remote attacker could
possibly use this issue to cause kadmind to crash, resulting in a denial
of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs becaus
vendor_msrc·2023-08-08·CVSS 6.5
CVE-2023-36054 [MEDIUM] CWE-824 lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs becaus
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October
Red Hat
krb5: Denial of service through freeing uninitialized pointer
vendor_redhat·2023-08-07·CVSS 6.5
CVE-2023-36054 [MEDIUM] CWE-824 krb5: Denial of service through freeing uninitialized pointer
krb5: Denial of service through freeing uninitialized pointer
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
A vulnerability was found in the _xdr_kadm5_principal_ent_rec() function in lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (krb5). This issue occurs due to lack of validation in the relationship between n_key_data and the key_data array count, leading to the freeing of uninitialized pointers. This may allow a remote authenticated attacker to send a specially crafted request that causes the kadmind process to crash, result
Debian
CVE-2023-36054: krb5 - lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x b...
vendor_debian·2023·CVSS 6.5
CVE-2023-36054 [MEDIUM] CVE-2023-36054: krb5 - lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x b...
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
Scope: local
bookworm: resolved (fixed in 1.20.1-2+deb12u1)
bullseye: resolved (fixed in 1.18.3-6+deb11u4)
forky: resolved (fixed in 1.20.1-3)
sid: resolved (fixed in 1.20.1-3)
trixie: resolved (fixed in 1.20.1-3)
OSV
CVE-2023-36054: lib/kadm5/kadm_rpc_xdr
osv·2023-08-07·CVSS 6.5
CVE-2023-36054 [MEDIUM] CVE-2023-36054: lib/kadm5/kadm_rpc_xdr
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
GHSA
GHSA-39q6-4vrm-fv3g: lib/kadm5/kadm_rpc_xdr
ghsa_unreviewed·2023-08-07
CVE-2023-36054 [MEDIUM] CWE-824 GHSA-39q6-4vrm-fv3g: lib/kadm5/kadm_rpc_xdr
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
No detection rules found.
No public exploits indexed.
https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cddhttps://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-finalhttps://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-finalhttps://lists.debian.org/debian-lts-announce/2023/10/msg00031.htmlhttps://security.netapp.com/advisory/ntap-20230908-0004/https://web.mit.edu/kerberos/www/advisories/https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cddhttps://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-finalhttps://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-finalhttps://lists.debian.org/debian-lts-announce/2023/10/msg00031.htmlhttps://security.netapp.com/advisory/ntap-20230908-0004/https://web.mit.edu/kerberos/www/advisories/
2023-08-07
Published