V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2015-2696
DEB
Medium

lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers …

CVSS
4.3
Medium
EPSS
0.11
p93
Published
2015-01-01
Updated
2015-01-01
Description

lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gss_inquire_context call.

Tags · CWE
CWE-18
CWE-843
Affected products
Debian_linux
CVSS vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.108 · p93
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
krb5Tracked
krb5Tracked
krb5Tracked
krb5Tracked
krb5Tracked
debian_linux*Tracked
kerberos_5*Tracked
leap*Tracked
linux_enterprise_desktop*Tracked
linux_enterprise_server*Tracked
linux_enterprise_software_development_kit*Tracked
opensuse*Tracked
ubuntu_linux*Tracked
Source databases
DEB
CVE
UBU