cbcvebase.

Debian Krb5 vulnerabilities

121 known vulnerabilities affecting debian/krb5.

Total CVEs
121
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL13HIGH31MEDIUM47LOW30

Vulnerabilities

Page 2 of 7
CVE-2012-1015P3CRITICALCVSS 9.3fixed in krb5 1.10.1+dfsg-2 (bookworm)2012
CVE-2012-1015 [CRITICAL] CVE-2012-1015: krb5 - The kdc_handle_protected_negotiation function in the Key Distribution Center (KD... The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x before 1.10.3 attempts to calculate a checksum before verifying that the key type is appropriate for a checksum, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointe
debian
CVE-2007-4000P3HIGHCVSS 8.5fixed in krb5 1.6.dfsg.1-7 (bookworm)2007
CVE-2007-4000 [HIGH] CVE-2007-4000: krb5 - The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the K... The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigg
debian
CVE-2016-3119P3MEDIUMCVSS 5.3fixed in krb5 1.14.2+dfsg-1 (bookworm)2016
CVE-2016-3119 [MEDIUM] CVE-2016-3119: krb5 - The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c i... The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal. Sc
debian
CVE-2009-4212P3CRITICALCVSS 10.0fixed in krb5 1.8+dfsg~alpha1-1 (bookworm)2009
CVE-2009-4212 [CRITICAL] CVE-2009-4212: krb5 - Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality ... Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid. Scope: local bookworm: res
debian
CVE-2021-36222P3HIGHCVSS 7.5fixed in krb5 1.18.3-6 (bookworm)2021
CVE-2021-36222 [HIGH] CVE-2021-36222: krb5 - ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Ke... ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation. Scope: local bookworm: resolved (fixed in 1.18.3-6) bullseye: resolved
debian
CVE-2009-0846P3CRITICALCVSS 10.0fixed in krb5 1.6.dfsg.4~beta1-13 (bookworm)2009
CVE-2009-0846 [CRITICAL] CVE-2009-0846: krb5 - The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.... The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer. Scope: local bookworm:
debian
CVE-2005-1175P3MEDIUMCVSS 7.5fixed in krb5 1.3.6-4 (bookworm)2005
CVE-2005-1175 [HIGH] CVE-2005-1175: krb5 - Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos ... Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain valid TCP or UDP request. Scope: local bookworm: resolved (fixed in 1.3.6-4) bullseye: resolved (fixed in 1.3.6-4) forky: resolved (fixed in 1.
debian
CVE-2014-4343P3HIGHCVSS 7.6fixed in krb5 1.12.1+dfsg-5 (bookworm)2014
CVE-2014-4343 [HIGH] CVE-2014-4343: krb5 - Double free vulnerability in the init_ctx_reselect function in the SPNEGO initia... Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies
debian
CVE-2017-11462P3LOWCVSS 9.8fixed in krb5 1.15.2-1 (bookworm)2017
CVE-2017-11462 [CRITICAL] CVE-2017-11462: krb5 - Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have ... Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error. Scope: local bookworm: resolved (fixed in 1.15.2-1) bullseye: resolved (fixed in 1.15.2-1) forky: resolved (fixed in 1.15.2-1) sid: resolved (fixed in 1.15.2-1) trixie: resolved (fixed in 1.15.2-1
debian
CVE-2008-0062P3HIGHCVSS 9.8fixed in krb5 1.6.dfsg.3~beta1-4 (bookworm)2008
CVE-2008-0062 [CRITICAL] CVE-2008-0062: krb5 - KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 mes... KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free. Scope: local bookworm: resolved (fixed in 1.6.dfsg.3~beta1-4) bullseye: resolved (fixed in 1.6.df
debian
CVE-2011-0284P3LOWCVSS 7.6fixed in krb5 1.8.3+dfsg-6 (bookworm)2011
CVE-2011-0284 [HIGH] CVE-2011-0284: krb5 - Double free vulnerability in the prepare_error_as function in do_as_req.c in the... Double free vulnerability in the prepare_error_as function in do_as_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 through 1.9, when the PKINIT feature is enabled, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an e_data field containing typed data. Scope: local bookworm: resolved (f
debian
CVE-2012-1014P3CRITICALCVSS 9.0fixed in krb5 1.10.1+dfsg-2 (bookworm)2012
CVE-2012-1014 [CRITICAL] CVE-2012-1014: krb5 - The process_as_req function in the Key Distribution Center (KDC) in MIT Kerberos... The process_as_req function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.10.x before 1.10.3 does not initialize a certain structure member, which allows remote attackers to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a malformed AS-REQ request. Scope: local bookworm: reso
debian
CVE-2008-0948P3LOWCVSS 9.3fixed in krb5 1.3-1 (bookworm)2008
CVE-2008-0948 [CRITICAL] CVE-2008-0948: krb5 - Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc ... Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering a large number of
debian
CVE-2007-4743P3HIGHCVSS 10.0fixed in krb5 1.6.dfsg.1-7 (bookworm)2007
CVE-2007-4743 [CRITICAL] CVE-2007-4743: krb5 - The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC lib... The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and other applications that use krb5, does not correctly check the buffer length in some environments and architectures, which might allow remote attackers to conduct a buffer overflow
debian
CVE-2005-1689P3MEDIUMCVSS 9.8fixed in krb5 1.3.6-4 (bookworm)2005
CVE-2005-1689 [CRITICAL] CVE-2005-1689: krb5 - Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5)... Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions. Scope: local bookworm: resolved (fixed in 1.3.6-4) bullseye: resolved (fixed in 1.3.6-4) forky: resolved (fixed in 1.3.6-4) sid: resolved (fixed in 1.3.6-4) trixie: resolved (fixed in 1.3.6-
debian
CVE-2020-28196P3HIGHCVSS 7.5fixed in krb5 1.18.3-1 (bookworm)2020
CVE-2020-28196 [HIGH] CVE-2020-28196: krb5 - MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounde... MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit. Scope: local bookworm: resolved (fixed in 1.18.3-1) bullseye: resolved (fixed in 1.18.3-1) forky: resolved (fixed in 1.18.3-1) sid: resolved
debian
CVE-2003-0028P3CRITICALCVSS 9.8fixed in dietlibc 0.22-2 (bookworm)2003
CVE-2003-0028 [CRITICAL] CVE-2003-0028: dietlibc - Integer overflow in the xdrmem_getbytes() function, and possibly other functions... Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391. Scope: local bookworm: resol
debian
CVE-2007-5902P3LOWCVSS 10.0fixed in krb5 1.6.dfsg.4~beta1-1 (bookworm)2007
CVE-2007-5902 [CRITICAL] CVE-2007-5902: krb5 - Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_g... Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request. Scope: local bookworm: resolved (fixed in 1.6.dfsg.4~beta1-1) bullseye: resolved (fixed in 1.6.dfsg.4~beta1-1) forky: resolved (fixed in 1.6.df
debian
CVE-2005-0469P3HIGHCVSS 7.5fixed in heimdal 0.6.3-10 (bookworm)2005
CVE-2005-0469 [HIGH] CVE-2005-0469: heimdal - Buffer overflow in the slc_add_reply function in various BSD-based Telnet client... Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands. Scope: local bookworm: resolved (fixed in 0.6.3-10) bullseye: resolved (fixed in 0.6.3-10) forky: resolved (fixed in 0.6.3-10) sid:
debian
CVE-2024-37370P3HIGHCVSS 7.5fixed in krb5 1.20.1-2+deb12u2 (bookworm)2024
CVE-2024-37370 [HIGH] CVE-2024-37370: krb5 - In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext... In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application. Scope: local bookworm: resolved (fixed in 1.20.1-2+deb12u2) bullseye: resolved (fixed in 1.18.3-6+deb11u5) forky: resolved (fixed in 1.21.3-1) sid: resolved (fixed i
debian
Debian Krb5 vulnerabilities | cvebase