cbcvebase.

Debian Krb5 vulnerabilities

121 known vulnerabilities affecting debian/krb5.

Total CVEs
121
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL13HIGH31MEDIUM47LOW30

Vulnerabilities

Page 5 of 7
CVE-2014-9423P4MEDIUMCVSS 5.0fixed in krb5 1.12.1+dfsg-17 (bookworm)2014
CVE-2014-9423 [MEDIUM] CVE-2014-9423: krb5 - The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Ker... The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field. Scope: loc
debian
CVE-2003-0139P4HIGHCVSS 7.5fixed in krb5 1.2.7-3 (bookworm)2003
CVE-2003-0139 [HIGH] CVE-2003-0139: krb5 - Certain weaknesses in the implementation of version 4 of the Kerberos protocol (... Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing." Scope: local bookworm: resolved (fixed in 1.2.7-3) bullseye: resolved (fixed in 1.2.7-3)
debian
CVE-2018-20217P4LOWCVSS 5.3fixed in krb5 1.16.2-1 (bookworm)2018
CVE-2018-20217 [MEDIUM] CVE-2018-20217: krb5 - A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb... A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DES, triple-DES, or RC4), the attacker can crash the KDC by making an S4U2Self request. Scope: local bookworm: resolved (fixed in 1.16.2-1) bullseye: resolved (fixed in 1.16.2-1) forky: resolv
debian
CVE-2006-3084P4MEDIUMCVSS 7.2fixed in krb5 1.4.3-9 (bookworm)2006
CVE-2006-3084 [HIGH] CVE-2006-3084: krb5 - The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.... The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which might allow local users to gain privileges by causing setuid to fail to drop privileges. NOTE: as of 20060808, it is not known whether an exploitable attack scenario exists for these issues.
debian
CVE-2009-0845P4MEDIUMCVSS 5.0fixed in krb5 1.6.dfsg.4~beta1-13 (bookworm)2009
CVE-2009-0845 [MEDIUM] CVE-2009-0845: krb5 - The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in... The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token. Scope: local bookworm: resolved (fixed in 1.6.dfsg
debian
CVE-2013-1415P4LOWCVSS 5.0fixed in krb5 1.10.1+dfsg-4 (bookworm)2013
CVE-2013-1415 [MEDIUM] CVE-2013-1415: krb5 - The pkinit_check_kdc_pkid function in plugins/preauth/pkinit/pkinit_crypto_opens... The pkinit_check_kdc_pkid function in plugins/preauth/pkinit/pkinit_crypto_openssl.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 and 1.11.x before 1.11.1 does not properly handle errors during extraction of fields from an X.509 certificate, which allows remote attackers to cause a denial of service (NULL
debian
CVE-2012-1012P4MEDIUMCVSS 5.5fixed in krb5 1.10.1+dfsg-1 (bookworm)2012
CVE-2012-1012 [MEDIUM] CVE-2012-1012: krb5 - server/server_stubs.c in the kadmin protocol implementation in MIT Kerberos 5 (a... server/server_stubs.c in the kadmin protocol implementation in MIT Kerberos 5 (aka krb5) 1.10 before 1.10.1 does not properly restrict access to (1) SET_STRING and (2) GET_STRINGS operations, which might allow remote authenticated administrators to modify or read string attributes by leveraging the global list privilege. Scope: local bookworm: resolved (fixed in 1.10.1
debian
CVE-2014-4341P4MEDIUMCVSS 5.0fixed in krb5 1.12.1+dfsg-4 (bookworm)2014
CVE-2014-4341 [MEDIUM] CVE-2014-4341: krb5 - MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denia... MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session. Scope: local bookworm: resolved (fixed in 1.12.1+dfsg-4) bullseye: resolved (fixed in 1.12.1+dfsg-4) forky: resolved (fixed in 1.12.1+dfsg-4) sid: resolved (fixed in 1.12.1+d
debian
CVE-2011-1530P4MEDIUMCVSS 6.8fixed in krb5 1.10+dfsg~alpha1-7 (bookworm)2011
CVE-2011-1530 [MEDIUM] CVE-2011-1530: krb5 - The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC... The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS request that triggers an error other than the KRB5_KDB_NOENTRY error. Scope: local bookworm: resolved (fixed in 1.10+
debian
CVE-2014-4342P4MEDIUMCVSS 5.0fixed in krb5 1.12.1+dfsg-4 (bookworm)2014
CVE-2014-4342 [MEDIUM] CVE-2014-4342: krb5 - MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attac... MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session. Scope: local bookworm: resolved (fixed in 1.12.1+dfsg-4) bullseye: resolved (fixed in 1.12.1+dfsg-4) forky: resolved (fixed
debian
CVE-2009-0844P4MEDIUMCVSS 5.8fixed in krb5 1.6.dfsg.4~beta1-13 (bookworm)2009
CVE-2009-0844 [MEDIUM] CVE-2009-0844: krb5 - The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka... The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read. Scope: local bookworm: resolved (fixed in 1.6.dfsg.4~beta1-13) bullseye: resolved (fixed in 1.6
debian
CVE-2013-1418P4LOWCVSS 4.3fixed in krb5 1.11.3+dfsg-3+nmu1 (bookworm)2013
CVE-2013-1418 [MEDIUM] CVE-2013-1418: krb5 - The setup_server_realm function in main.c in the Key Distribution Center (KDC) i... The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request. Scope: local bookworm: resolved (fixed in 1.11.3+dfsg-3+nmu1) bullseye: resolved (fixed in
debian
CVE-2010-4022P4LOWCVSS 5.0fixed in krb5 1.8.3+dfsg-5 (bookworm)2010
CVE-2010-4022 [MEDIUM] CVE-2010-4022: krb5 - The do_standalone function in the MIT krb5 KDC database propagation daemon (kpro... The do_standalone function in the MIT krb5 KDC database propagation daemon (kpropd) in Kerberos 1.7, 1.8, and 1.9, when running in standalone mode, does not properly handle when a worker child process "exits abnormally," which allows remote attackers to cause a denial of service (listening process termination, no new connections, and lack of updates in slave KVC) via u
debian
CVE-2010-0628P4MEDIUMCVSS 5.0fixed in krb5 1.8+dfsg-1.1 (bookworm)2010
CVE-2010-0628 [MEDIUM] CVE-2010-0628: krb5 - The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in... The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in the SPNEGO GSS-API functionality in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2 and 1.8 before 1.8.1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid packet that triggers incorrect preparation of an error token. Scope: local bookworm:
debian
CVE-2011-0281P4MEDIUMCVSS 5.0fixed in krb5 1.8.3+dfsg-5 (bookworm)2011
CVE-2011-0281 [MEDIUM] CVE-2011-0281: krb5 - The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos ... The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (file descriptor exhaustion and daemon hang) via a principal name that triggers use of a backslash escape sequence, as demonstrated by a \n sequence. Scope: local bookworm: res
debian
CVE-2011-0282P4MEDIUMCVSS 5.0fixed in krb5 1.8.3+dfsg-5 (bookworm)2011
CVE-2011-0282 [MEDIUM] CVE-2011-0282: krb5 - The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9... The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer dereference or buffer over-read, and daemon crash) via a crafted principal name. Scope: local bookworm: resolved (fixed in 1.8.3+dfsg-5) bullseye: resolved (fixed in 1.8.3+dfsg-5) forky: resol
debian
CVE-2018-5729P4MEDIUMCVSS 4.7fixed in krb5 1.16.1-1 (bookworm)2018
CVE-2018-5729 [MEDIUM] CVE-2018-5729: krb5 - MIT krb5 1.6 or later allows an authenticated kadmin with permission to add prin... MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module. Scope: local bookworm: resolved (fixed in 1.16.1-1) bullseye: resolved (fixed in 1.16.1-1) forky: reso
debian
CVE-2012-1016P4MEDIUMCVSS 5.0fixed in krb5 1.10.1+dfsg-4+nmu1 (bookworm)2012
CVE-2012-1016 [MEDIUM] CVE-2012-1016: krb5 - The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c ... The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 attempts to find an agility KDF identifier in inappropriate circumstances, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via
debian
CVE-2003-0059P4HIGHCVSS 7.5fixed in krb5 1.2.5-1 (bookworm)2003
CVE-2003-0059 [HIGH] CVE-2003-0059: krb5 - Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos... Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys. Scope: local bookworm: resolved (fixed in 1.2.5-1) bullseye: resolved (fixed in 1.2.5-1) forky: resolved (fixed in 1.2.5-1) sid: resolved (fixed in 1.2.5-1) trixie: resolved
debian
CVE-2004-0644P4MEDIUMCVSS 5.0fixed in krb5 1.3.4-3 (bookworm)2004
CVE-2004-0644 [MEDIUM] CVE-2004-0644: krb5 - The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (k... The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding. Scope: local bookworm: resolved (fixed in 1.3.4-3) bullseye: resolved (fixed in 1.3.4-3) forky: resolved (fixed in 1.3.4-3) sid: resolved (fixed in 1.3.4-3) trixie: reso
debian
Debian Krb5 vulnerabilities | cvebase