CVE-2015-8629
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive…
Does this matter?
Lower severity and a low EPSS score (3.66%). Track it; it rarely justifies an emergency change on its own.
Description
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.66% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- mit/kerberos 5 · oracle/linux · oracle/solaris · debian/debian linux · opensuse/leap · opensuse/opensuse · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8341Vendor Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00110.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0493.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0532.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3466Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlThird Party Advisory
- http://www.securityfocus.com/bid/82801Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034914Third Party Advisory, VDB Entry
- https://github.com/krb5/krb5/commit/df17a1224a3406f57477bcd372c61e04c0e5a5bbPatch, Third Party Advisory
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=8341Vendor Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00110.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0493.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0532.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3466Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlThird Party Advisory
- http://www.securityfocus.com/bid/82801Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034914Third Party Advisory, VDB Entry
- https://github.com/krb5/krb5/commit/df17a1224a3406f57477bcd372c61e04c0e5a5bbPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.