MIT krb5 lib/gssapi/krb5/iakerb. c DoS Vulnerability (CVE-2015-2696)
MIT krb5 lib/gssapi/krb5/iakerb. c DoS Vulnerability (CVE-2015-2696)
Release date:
Updated on:
Affected Systems:
MIT Kerberos 5 <1.14
Description:
CVE (CAN) ID: CVE-2015-2696
Kerberos is a widely used super-powerful encryption to verify the network protocol between the client and the server.
MIT Kerberos 5 (krb5) earlier than 1.14, lib/gssapi/krb5/iakerb. c uses an inappropriate context handle. Remote attackers use a constructed IAKERB packet to handle errors in gss_inquire_context calls. This may cause pointer read errors and process crashes, resulting in DOS.
<* Source: ghudson
*>
Suggestion:
Vendor patch:
MIT
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://krbdev.mit.edu/rt/Ticket/Display.html? Id = 8244
Https://github.com/krb5/krb5/commit/e04f0283516e80d2f93366e0d479d13c9b5c8c2a
This article permanently updates the link address: