Debian Krb5 vulnerabilities
121 known vulnerabilities affecting debian/krb5.
Total CVEs
121
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL13HIGH31MEDIUM47LOW30
Vulnerabilities
Page 6 of 7
CVE-2010-1324P4LOWCVSS 3.7fixed in krb5 1.8.3+dfsg-3 (bookworm)2010
CVE-2010-1324 [LOW] CVE-2010-1324: krb5 - MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determ...
MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum, (2) an unkeyed PAC checksum, or (3) a KrbFastArmoredReq checksum based on an RC4 key.
Scope: local
bookworm: resolved (fixe
debian
CVE-2015-2697P4MEDIUMCVSS 4.0fixed in krb5 1.13.2+dfsg-3 (bookworm)2015
CVE-2015-2697 [MEDIUM] CVE-2015-2697: krb5 - The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (a...
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
Scope: local
bookworm: resolved (fixed in 1.13.2+dfsg-3)
bullseye: resolved (fixed in 1.13.2+dfsg-
debian
CVE-2014-5353P4LOWCVSS 3.5fixed in krb5 1.12.1+dfsg-16 (bookworm)2014
CVE-2014-5353 [LOW] CVE-2014-5353: krb5 - The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ld...
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password policy.
Scope: lo
debian
CVE-2012-1013P4LOWCVSS 4.0fixed in krb5 1.10.1+dfsg-3 (bookworm)2012
CVE-2012-1013 [MEDIUM] CVE-2012-1013: krb5 - The check_1_6_dummy function in lib/kadm5/srv/svr_principal.c in kadmind in MIT ...
The check_1_6_dummy function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x, and 1.10.x before 1.10.2 allows remote authenticated administrators to cause a denial of service (NULL pointer dereference and daemon crash) via a KRB5_KDB_DISALLOW_ALL_TIX create request that lacks a password.
Scope: local
bookworm: resolved (fixed in 1.
debian
CVE-2010-1323P4LOWCVSS 3.7fixed in krb5 1.8.3+dfsg-3 (bookworm)2010
CVE-2010-1323 [LOW] CVE-2010-1323: krb5 - MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1...
MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that (1) are unkeyed or (2) use RC4 keys.
Scope: local
debian
CVE-2005-1174P4MEDIUMCVSS 5.0fixed in krb5 1.3.6-4 (bookworm)2005
CVE-2005-1174 [MEDIUM] CVE-2005-1174: krb5 - MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows rem...
MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.
Scope: local
bookworm: resolved (fixed in 1.3.6-4)
bullseye: resolved (fixed in 1.3.6-4)
forky: resolved (fixed in 1.3.6-4)
sid: resolved (fixed in 1.3
debian
CVE-2004-0643P4MEDIUMCVSS 4.6fixed in krb5 1.3.4-3 (bookworm)2004
CVE-2004-0643 [MEDIUM] CVE-2004-0643: krb5 - Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5)...
Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 1.3.4-3)
bullseye: resolved (fixed in 1.3.4-3)
forky: resolved (fixed in 1.3.4-3)
sid: resolved (fixed in 1.3.4-3)
trixie: resolved (fixed in 1.3.4-3)
debian
CVE-2013-1416P4LOWCVSS 4.0fixed in krb5 1.10.1+dfsg-5 (bookworm)2013
CVE-2013-1416 [MEDIUM] CVE-2013-1416: krb5 - The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (...
The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS-REQ request.
Scope: local
bookworm: resolved (fixed
debian
CVE-2018-5730P4LOWCVSS 3.8fixed in krb5 1.16.1-1 (bookworm)2018
CVE-2018-5730 [LOW] CVE-2018-5730: krb5 - MIT krb5 1.6 or later allows an authenticated kadmin with permission to add prin...
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
Scope: local
bookworm:
debian
CVE-2003-0058P4MEDIUMCVSS 5.0fixed in krb5 1.2.5-1 (bookworm)2003
CVE-2003-0058 [MEDIUM] CVE-2003-0058: krb5 - MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authent...
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
Scope: local
bookworm: resolved (fixed in 1.2.5-1)
bullseye: resolved (fixed in 1.2.5-1)
forky: resolved (fixed in 1.2.5-1)
sid: resolved (fixed
debian
CVE-2003-0082P4MEDIUMCVSS 5.0fixed in krb5 1.3.3-2 (bookworm)2003
CVE-2003-0082 [MEDIUM] CVE-2003-0082: krb5 - The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows ...
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").
Scope: local
bookworm: resolved (fixed in 1.3.3-2)
bullseye: resolved (fixed in 1.3.3-2)
forky
debian
CVE-2003-0072P4MEDIUMCVSS 5.0fixed in krb5 1.2.7-3 (bookworm)2003
CVE-2003-0072 [MEDIUM] CVE-2003-0072: krb5 - The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows ...
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").
Scope: local
bookworm: resolved (fixed in 1.2.7-3)
bullseye: resolved (fixed in 1.2.7-3)
f
debian
CVE-2024-26462P4MEDIUMCVSS 5.5fixed in krb5 1.20.1-2+deb12u3 (bookworm)2024
CVE-2024-26462 [MEDIUM] CVE-2024-26462: krb5 - Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/k...
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
Scope: local
bookworm: resolved (fixed in 1.20.1-2+deb12u3)
bullseye: resolved
forky: resolved (fixed in 1.21.3-1)
sid: resolved (fixed in 1.21.3-1)
trixie: resolved (fixed in 1.21.3-1)
debian
CVE-2014-5354P4LOWCVSS 3.5fixed in krb5 1.12.1+dfsg-16 (bookworm)2014
CVE-2014-5354 [LOW] CVE-2014-5354: krb5 - plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12...
plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by creating a database entry for a keyless principal, as demonstrated by a kadmin "add_principal -nokey" or "purgekeys -all" command.
debian
CVE-2014-5351P4LOWCVSS 2.1fixed in krb5 1.12.1+dfsg-10 (bookworm)2014
CVE-2014-5351 [LOW] CVE-2014-5351: krb5 - The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmi...
The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a response to a -randkey -keepold request, which allows remote authenticated users to forge tickets by leveraging administrative access.
Scope: local
bookworm: resolved (fixed in 1.12.1+dfsg-10)
bullseye: resolved (fixed in 1.12.1+d
debian
CVE-2009-0847P4MEDIUMCVSS 4.3fixed in krb5 1.6.dfsg.4~beta1-13 (bookworm)2009
CVE-2009-0847 [MEDIUM] CVE-2009-0847: krb5 - The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6...
The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.
Scope: local
bookworm: resolved (fixed in 1.6.dfsg.4~beta1-13)
bul
debian
CVE-2007-5901P4LOWCVSS 6.9fixed in krb5 1.6.dfsg.4~beta1-1 (bookworm)2007
CVE-2007-5901 [MEDIUM] CVE-2007-5901: krb5 - Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/me...
Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors. NOTE: this might be the result of a typo in the source code.
Scope: local
bookworm: resolved (fixed in 1.6.dfsg.4~beta1-1)
bullseye: resolved (fixed in 1.6.dfsg.4~beta1-1)
forky: resolved (fixed in 1.6.dfs
debian
CVE-2010-4021P4LOWCVSS 2.1fixed in krb5 1.8+dfsg~alpha1-1 (bookworm)2010
CVE-2010-4021 [LOW] CVE-2010-4021: krb5 - The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not prop...
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request, aka a "KrbFastReq forgery issue."
Scope: local
bookworm: resolved (fixed in 1.8+dfsg~alpha1-1)
bullseye: resolved (fixed in 1.
debian
CVE-2013-1417P4LOWCVSS 3.5fixed in krb5 1.11.3+dfsg-3+nmu1 (bookworm)2013
CVE-2013-1417 [LOW] CVE-2013-1417: krb5 - do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1...
do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.11 before 1.11.4, when a single-component realm name is used, allows remote authenticated users to cause a denial of service (daemon crash) via a TGS-REQ request that triggers an attempted cross-realm referral for a host-based service principal.
Scope: local
bookworm: resolved (fixed in 1.11.
debian
CVE-2007-5971P4LOWCVSS 6.9fixed in krb5 1.6.dfsg.4~beta1-1 (bookworm)2007
CVE-2007-5971 [MEDIUM] CVE-2007-5971: krb5 - Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/...
Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors.
Scope: local
bookworm: resolved (fixed in 1.6.dfsg.4~beta1-1)
bullseye: resolved (fixed in 1.6.dfsg.4~beta1-1)
forky: resolved (fixed in 1.6.dfsg.4~beta1-1)
sid: resolved (fixed in 1.6.dfsg.4~beta1-1)
tri
debian