MIT Kerberos 5 kadmind Denial of Service Vulnerability (CVE-2015-8630)
MIT Kerberos 5 kadmind Denial of Service Vulnerability (CVE-2015-8630)
Release date:
Updated on:
Affected Systems:
MIT Kerberos 5 <1.14.1
MIT Kerberos 5 <1.14.1
MIT Kerberos 5 <1.13.4
MIT Kerberos 5 <1.13.4
MIT Kerberos 5 1.12.x
Description:
CVE (CAN) ID: CVE-2015-8630
Kerberos is a widely used super-powerful encryption to verify the network protocol between the client and the server.
MIT Kerberos 5 versions earlier than 1.12.x, 1.13.4, and earlier than 1.14.1. The kadmind/lib/kadm5/srv/svr_principal.c/kadm5_create_principal_3 and kadm5_modify_principal functions have security vulnerabilities. By specifying the KADM5_POLICY with an empty Policy Name, a remote user can cause a denial of service.
<* Source: anonymous
*>
Suggestion:
Vendor patch:
MIT
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://krbdev.mit.edu/rt/Ticket/Display.html? Id = 8342
Https://github.com/krb5/krb5/commit/b863de7fbf080b15e347a736fdda0a82d42f4f6b
This article permanently updates the link address: