Lucene search

K
redhatcveRedhat.comRH:CVE-2017-15088
HistoryOct 26, 2017 - 1:19 p.m.

CVE-2017-15088

2017-10-2613:19:01
redhat.com
access.redhat.com
11

EPSS

0.021

Percentile

89.1%

A stack based buffer overflow was found in the get_matching_data() function, when reading the principal’s certificate during pkinit preauthentication. If the Certifcate Authority’s subject line is sufficiently long, an attacker able to have a specially crafted certificate signed could crash the authentication process, such as kinit, or, possibly, run arbitrary code.