MIT Kerberos 5 kadmind Memory leakage Vulnerability (CVE-2015-8631)
MIT Kerberos 5 kadmind Memory leakage Vulnerability (CVE-2015-8631)
Release date:
Updated on:
Affected Systems:
MIT Kerberos 5 <1.14.1
MIT Kerberos 5 <1.14.1
MIT Kerberos 5 <1.13.4
MIT Kerberos 5 <1.13.4
Description:
CVE (CAN) ID: CVE-2015-8631
Kerberos is a widely used super-powerful encryption to verify the network protocol between the client and the server.
For versions earlier than MIT Kerberos 5 1.13.4 and earlier than 1.14.1, kadmind/kadmin/server/server_stubs.c has multiple memory leakage vulnerabilities. By specifying a request with an empty Policy Name, a remote user can cause a denial of service.
<* Source: anonymous
*>
Suggestion:
Vendor patch:
MIT
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://krbdev.mit.edu/rt/Ticket/Display.html? Id = 8343
Https://github.com/krb5/krb5/commit/83ed75feba32e46f736fcce0d96a0445f29b96c2
This article permanently updates the link address: