3.5
CVSSv2

CVE-2013-1417

Published: 20/11/2013 Updated: 21/01/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.11 prior to 1.11.4, when a single-component realm name is used, allows remote authenticated users to cause a denial of service (daemon crash) via a TGS-REQ request that triggers an attempted cross-realm referral for a host-based service principal.

Vulnerable Product Search on Vulmon Subscribe to Product

mit kerberos 5 1.11.2

mit kerberos 5 1.11.1

mit kerberos 5 1.11

mit kerberos 5 1.11.3

Vendor Advisories

Debian Bug report logs - #730085 krb5: CVE-2013-1417 Package: krb5; Maintainer for krb5 is Sam Hartman <hartmans@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 21 Nov 2013 06:57:01 UTC Severity: important Tags: fixed-upstream, patch, security, upstream Found in version 1113+dfsg-3 Fi ...