Lucene search

K
redosRedosROS-20240911-04
HistorySep 11, 2024 - 12:00 a.m.

ROS-20240911-04

2024-09-1100:00:00
redos.red-soft.ru
12
kerberos
vulnerability
network authentication
gss krb5 token
system integrity
remote attackers
information confidentiality
memory read
availability

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

AI Score

7.2

Confidence

Low

A vulnerability in the Kerberos network authentication protocol is associated with modification of the Extra Count open field
of the confidential GSS krb5 shell token. Exploitation of the vulnerability allows an attacker acting remotely to affect the integrity and operation of the system.
remotely to affect the integrity and operation of the system

A vulnerability in the Kerberos network authentication protocol is related to causing a memory read during the
GSS message token processing. Exploitation of the vulnerability allows a remote attacker,
affect confidentiality, integrity and availability of protected information

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64krb5-server< 1.20.1-4UNKNOWN

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

AI Score

7.2

Confidence

Low