MIT krb5 build_principal_va Denial of Service Vulnerability (CVE-2015-2697)
MIT krb5 build_principal_va Denial of Service Vulnerability (CVE-2015-2697)
Release date:
Updated on:
Affected Systems:
MIT Kerberos 5 <1.14
Description:
CVE (CAN) ID: CVE-2015-2697
Kerberos is a widely used super-powerful encryption to verify the network protocol between the client and the server.
Before MIT Kerberos 5 (krb5) 1.14, The build_principal_va function of lib/krb5/krb/bld_princ.c processes the '\ 0' character at the start position of the long realm field in the TGS request, this will cause out-of-bounds read and KDC crash, resulting in denial of service.
<* Source: ghudson
*>
Suggestion:
Vendor patch:
MIT
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://krbdev.mit.edu/rt/Ticket/Display.html? Id = 8244
Https://github.com/krb5/krb5/commit/e04f0283516e80d2f93366e0d479d13c9b5c8c2a
This article permanently updates the link address: