Debian Krb5 vulnerabilities
121 known vulnerabilities affecting debian/krb5.
Total CVEs
121
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL13HIGH31MEDIUM47LOW30
Vulnerabilities
Page 4 of 7
CVE-2016-3120P4MEDIUMCVSS 6.5fixed in krb5 1.14.3+dfsg-1 (bookworm)2016
CVE-2016-3120 [MEDIUM] CVE-2016-3120: krb5 - The validate_as_request function in kdc_util.c in the Key Distribution Center (K...
The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client data structure, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an S4U2Self reques
debian
CVE-2017-11368P4MEDIUMCVSS 6.5fixed in krb5 1.15.1-2 (bookworm)2017
CVE-2017-11368 [MEDIUM] CVE-2017-11368: krb5 - In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause ...
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
Scope: local
bookworm: resolved (fixed in 1.15.1-2)
bullseye: resolved (fixed in 1.15.1-2)
forky: resolved (fixed in 1.15.1-2)
sid: resolved (fixed in 1.15.1-2)
trixie: resolved (fixed in 1.15.1-2)
debian
CVE-2010-1321P4MEDIUMCVSS 6.8fixed in heimdal 1.4.0~git20100605.dfsg.1-1 (bookworm)2010
CVE-2010-1321 [MEDIUM] CVE-2010-1321: heimdal - The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library ...
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ m
debian
CVE-2015-2696P4HIGHCVSS 7.1fixed in krb5 1.13.2+dfsg-3 (bookworm)2015
CVE-2015-2696 [HIGH] CVE-2015-2696: krb5 - lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an i...
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gss_inquire_context call.
Scope: local
bookworm: resolved (fixed in 1.13.2+dfsg-3)
bullseye: resolved (fix
debian
CVE-2007-5894P4LOWCVSS 9.3fixed in krb5 1.6.dfsg.4~beta1-1 (bookworm)2007
CVE-2007-5894 [CRITICAL] CVE-2007-5894: krb5 - The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does no...
The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used. NOTE: the vendor disputes this issue, stating "
debian
CVE-2021-37750P4MEDIUMCVSS 6.5fixed in krb5 1.18.3-7 (bookworm)2021
CVE-2021-37750 [MEDIUM] CVE-2021-37750: krb5 - The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and...
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.
Scope: local
bookworm: resolved (fixed in 1.18.3-7)
bullseye: resolved (fixed in 1.18.3-6+deb11u1)
forky: resolved (fixed in 1.18.3-7)
sid: resolved (fixed in 1.18.3-7
debian
CVE-2010-0283P4HIGHCVSS 7.8fixed in krb5 1.8+dfsg~alpha1-7 (bookworm)2010
CVE-2010-0283 [HIGH] CVE-2010-0283: krb5 - The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2,...
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request.
Scope: local
bookworm: resolved (fixed in 1.8+dfsg~alpha1-7)
bullseye: resolved (fixed in 1.8+dfsg~alpha1-7)
forky: resolved (fixed in 1.
debian
CVE-2015-8631P4MEDIUMCVSS 6.5fixed in krb5 1.13.2+dfsg-5 (bookworm)2015
CVE-2015-8631 [MEDIUM] CVE-2015-8631: krb5 - Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos...
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
Scope: local
bookworm: resolved (fixed in 1.13.2+dfsg-5)
bullseye: resolved (fixed in 1.13.2+dfsg-5)
forky:
debian
CVE-2008-0063P4MEDIUMCVSS 7.5fixed in krb5 1.6.dfsg.3~beta1-4 (bookworm)2008
CVE-2008-0063 [HIGH] CVE-2008-0063: krb5 - The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clea...
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
Scope: local
bookworm: resolved (fixed in 1.6.dfsg.3~beta1-4)
bullseye: resolved (fixed in 1.6.dfsg.3~beta1-4)
forky: resolv
debian
CVE-2018-5710P4MEDIUMCVSS 6.5fixed in krb5 1.16.1-1 (bookworm)2018
CVE-2018-5710 [MEDIUM] CVE-2018-5710: krb5 - An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defin...
An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the Key Distribution Center (KDC), which allows remote authenticated users to cause a denial of service (NULL pointer dereference) via a modified kadmin client.
Scope: l
debian
CVE-2005-0488P4LOWCVSS 5.0fixed in krb5 1.8.3+dfsg-4 (bookworm)2005
CVE-2005-0488 [MEDIUM] CVE-2005-0488: krb5 - Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux...
Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
Scope: local
bookworm: resolved (fixed in 1.8.3+dfsg-4)
bullseye: resolved (fixed in 1.8.3+dfsg-4)
forky: resolved (fixed in 1.8.3+dfsg-4)
sid: resolve
debian
CVE-2003-0138P4HIGHCVSS 7.5fixed in heimdal 0.5.2-1 (bookworm)2003
CVE-2003-0138 [HIGH] CVE-2003-0138: heimdal - Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages...
Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.
Scope: local
bookworm: resolved (fixed in 0.5.2-1)
bullseye: resolved (fixed in 0.5.2-1)
forky: resolved (fixed in 0.5.2-1)
sid: resolved (fixed in 0.5.2-1)
trixie: resolved (fixed in 0.5.2-1)
debian
CVE-2015-8629P4MEDIUMCVSS 5.3fixed in krb5 1.13.2+dfsg-5 (bookworm)2015
CVE-2015-8629 [MEDIUM] CVE-2015-8629: krb5 - The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerber...
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string.
Scope: local
bookworm: resolved (
debian
CVE-2002-2443P4MEDIUMCVSS 5.0fixed in krb5 1.10.1+dfsg-6 (bookworm)2002
CVE-2002-2443 [MEDIUM] CVE-2002-2443: krb5 - schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1....
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.
Sc
debian
CVE-2015-2695P4MEDIUMCVSS 5.0fixed in krb5 1.13.2+dfsg-3 (bookworm)2015
CVE-2015-2695 [MEDIUM] CVE-2015-2695: krb5 - lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies ...
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
Scope: local
bookworm: resolved (fixed in 1.13.2+dfsg-3)
bullseye: reso
debian
CVE-2004-1189P4HIGHCVSS 7.2fixed in krb5 1.3.6-1 (bookworm)2004
CVE-2004-1189 [HIGH] CVE-2004-1189: krb5 - The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5...
The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.
debian
CVE-2006-3083P4MEDIUMCVSS 7.2fixed in krb5 1.4.3-9 (bookworm)2006
CVE-2006-3083 [HIGH] CVE-2006-3083: krb5 - The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5,...
The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.
Scope: local
bookworm: res
debian
CVE-2010-0629P4LOWCVSS 6.5fixed in krb5 1.7+dfsg-1 (bookworm)2010
CVE-2010-0629 [MEDIUM] CVE-2010-0629: krb5 - Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT K...
Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.
Scope: local
bookworm: resolved (fixed in 1.7+dfsg-1)
bullseye: resolved (fixed in 1.7+dfsg-1)
fo
debian
CVE-2003-0060P4HIGHCVSS 7.5fixed in krb5 1.2.4 (bookworm)2003
CVE-2003-0060 [HIGH] CVE-2003-0060: krb5 - Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Di...
Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.
Scope: local
bookworm: resolved (fixed in 1.2.4)
bullseye: resolved (fixed in 1.2.4)
forky: resolved (
debian
CVE-2014-5355P4MEDIUMCVSS 5.0fixed in krb5 1.12.1+dfsg-18 (bookworm)2014
CVE-2014-5355 [MEDIUM] CVE-2014-5355: krb5 - MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_me...
MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a '\0' character, which allows remote attackers to (1) cause a denial of service (NULL pointer dereference) via a zero-byte version string or (2) cause a denial of service (out-of-bounds read) by omitting the '\0' character, related to
debian