Debian Krb5 vulnerabilities
121 known vulnerabilities affecting debian/krb5.
Total CVEs
121
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL13HIGH31MEDIUM47LOW30
Vulnerabilities
Page 1 of 7
CVE-2011-4862P1HIGHCVSS 10.0ExploitedPoCfixed in heimdal 1.5.dfsg.1-1 (bookworm)2011
CVE-2011-4862 [CRITICAL] CVE-2011-4862: heimdal - Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MI...
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
Scope: local
bookworm: reso
debian
CVE-2002-1235P2CRITICALCVSS 10.0Exploitedfixed in heimdal 0.4e-22 (bookworm)2002
CVE-2002-1235 [CRITICAL] CVE-2002-1235: heimdal - The kadm_ser_in function in (1) the Kerberos v4compatibility administration daem...
The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows r
debian
CVE-2011-0285P2CRITICALCVSS 10.0PoCfixed in krb5 1.9.1+dfsg-1 (bookworm)2011
CVE-2011-0285 [CRITICAL] CVE-2011-0285: krb5 - The process_chpw_request function in schpw.c in the password-changing functional...
The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.
Scope: local
bookworm: resolved (fixed in 1.9.1
debian
CVE-2005-0468P3HIGHCVSS 7.5PoCfixed in krb5 1.3.6-2 (bookworm)2005
CVE-2005-0468 [HIGH] CVE-2005-0468: krb5 - Heap-based buffer overflow in the env_opt_add function in telnet.c for various B...
Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.
Scope: local
bookworm: resolved (fixed in 1.3.6-2)
bullseye: resolved (fixed in 1.3.6-2)
forky:
debian
CVE-2007-0956P3HIGHCVSS 10.0fixed in krb5 1.4.4-8 (bookworm)2007
CVE-2007-0956 [CRITICAL] CVE-2007-0956: krb5 - The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to ...
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.
Scope: local
bookworm: resolved (fixed in 1.4.4-8)
bullseye: resolved (fixed in 1.4.4-8)
forky: resolved (fixed in 1.4.4-8)
sid: resolved (fixed in 1.4.4-8)
trixie
debian
CVE-2002-0391P3CRITICALCVSS 9.8fixed in acm 5.0-10 (bookworm)2002
CVE-2002-0391 [CRITICAL] CVE-2002-0391: acm - Integer overflow in xdr_array function in RPC servers for operating systems that...
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
Scope: local
bookworm: resolved (fixed in 5.0-10)
bullseye: resolved (
debian
CVE-2022-42898P3HIGHCVSS 8.8fixed in heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)2022
CVE-2022-42898 [HIGH] CVE-2022-42898: heimdal - PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 ...
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb
debian
CVE-2007-3999P3HIGHCVSS 10.0fixed in krb5 1.6.dfsg.1-7 (bookworm)2007
CVE-2007-3999 [CRITICAL] CVE-2007-3999: krb5 - Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_...
Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably exe
debian
CVE-2017-15088P3LOWCVSS 9.8fixed in krb5 1.15.2-2 (bookworm)2017
CVE-2017-15088 [CRITICAL] CVE-2017-15088: krb5 - plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) thro...
plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) in situations involving untrusted X.509 data, related to the get_matching_data and X509_NAME_oneline_ex func
debian
CVE-2010-1320P4MEDIUMCVSS 4.0PoCfixed in krb5 1.8.1+dfsg-2 (bookworm)2010
CVE-2010-1320 [MEDIUM] CVE-2010-1320: krb5 - Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) i...
Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation.
Scope: local
bookworm: resolved (fixed in 1.8.1+dfsg-2)
bull
debian
CVE-2024-37371P3CRITICALCVSS 9.1fixed in krb5 1.20.1-2+deb12u2 (bookworm)2024
CVE-2024-37371 [CRITICAL] CVE-2024-37371: krb5 - In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory...
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
Scope: local
bookworm: resolved (fixed in 1.20.1-2+deb12u2)
bullseye: resolved (fixed in 1.18.3-6+deb11u5)
forky: resolved (fixed in 1.21.3-1)
sid: resolved (fixed in 1.21.3-1)
trixie: resolve
debian
CVE-2007-2442P3HIGHCVSS 10.0fixed in krb5 1.6.dfsg.1-5 (bookworm)2007
CVE-2007-2442 [CRITICAL] CVE-2007-2442: krb5 - The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) ...
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.
Scope: local
bookworm: resolved (fixed in 1.6.dfsg.1-5)
bullseye: resolved (fixed in 1.6.dfsg.1-5)
forky: resolv
debian
CVE-2014-4345P3HIGHCVSS 8.5fixed in krb5 1.12.1+dfsg-7 (bookworm)2014
CVE-2014-4345 [HIGH] CVE-2014-4345: krb5 - Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/li...
Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) 1.6.x through 1.11.x before 1.11.6 and 1.12.x before 1.12.2 allows remote authenticated users to cause a denial of service (buffer overflow) or possibly execute arbitrary code via a series of "cpw -keep
debian
CVE-2008-0947P3MEDIUMCVSS 10.0fixed in krb5 1.6.dfsg.3~beta1-4 (bookworm)2008
CVE-2008-0947 [CRITICAL] CVE-2008-0947: krb5 - Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos...
Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large number of open file descriptors.
Scope: local
bookworm: resolved (fixed in 1.6.dfsg.3~beta1-4)
bullseye: resolved (fixed in 1.6.dfsg.3~beta1-4)
forky: resolved (fixed in 1.6.dfsg.3~beta1-4)
debian
CVE-2007-0957P3HIGHCVSS 9.0fixed in krb5 1.4.4-8 (bookworm)2007
CVE-2007-0957 [CRITICAL] CVE-2007-0957: krb5 - Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 librar...
Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain format string specifier
debian
CVE-2014-5352P3CRITICALCVSS 9.0fixed in krb5 1.12.1+dfsg-17 (bookworm)2014
CVE-2014-5352 [CRITICAL] CVE-2014-5352: krb5 - The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_t...
The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly maintain security-context handles, which allows remote authenticated users to cause a denial of service (use-after-free and double free, and
debian
CVE-2007-1216P3HIGHCVSS 9.0fixed in krb5 1.4.4-8 (bookworm)2007
CVE-2007-1216 [CRITICAL] CVE-2007-1216: krb5 - Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), a...
Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an inva
debian
CVE-2004-0523P3CRITICALCVSS 10.0fixed in krb5 1.3.3-2 (bookworm)2004
CVE-2004-0523 [CRITICAL] CVE-2004-0523: krb5 - Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1...
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.
Scope: local
bookworm: resolved (fixed in 1.3.3-2)
bullseye: resolved (fixed in 1.3.3-2)
forky: resolved (fixed in 1.3.3-2)
sid: resolved (fixed in 1.3.3-2)
trixie: resolved (fixed in 1.3.3-2)
debian
CVE-2007-2798P3HIGHCVSS 9.0fixed in krb5 1.6.dfsg.1-5 (bookworm)2007
CVE-2007-2798 [CRITICAL] CVE-2007-2798: krb5 - Stack-based buffer overflow in the rename_principal_2_svc function in kadmind fo...
Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
Scope: local
bookworm: resolved (fixed in 1.6.dfsg.1-5)
bullseye: resolved (fixed in 1.6.dfsg.1-5)
forky: resolved (fixed in 1.6.dfsg.1-
debian
CVE-2014-9421P3CRITICALCVSS 9.0fixed in krb5 1.12.1+dfsg-17 (bookworm)2014
CVE-2014-9421 [CRITICAL] CVE-2014-9421: krb5 - The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerber...
The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly handle partial XDR deserialization, which allows remote authenticated users to cause a denial of service (use-after-free and double free, and daemon crash) or possibly execute arbitrary code
debian
1 / 7Next →