Lucene search

K
ubuntuUbuntuUSN-879-1
HistoryJan 06, 2010 - 12:00 a.m.

Kerberos vulnerability

2010-01-0600:00:00
ubuntu.com
49

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.5

Confidence

High

EPSS

0.895

Percentile

98.8%

Releases

  • Ubuntu 9.10

Packages

  • krb5 -

Details

Jeff Blaine, Radoslav Bodo, Jakob Haufe, and Jorgen Wahlsten discovered
that the Kerberos Key Distribution Center service did not correctly verify
certain network traffic. An unauthenticated remote attacker could send
a specially crafted request that would cause the KDC to crash, leading
to a denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu9.10noarchkrb5-kdc<Β 1.7dfsg~beta3-1ubuntu0.1UNKNOWN
Ubuntu9.10noarchkrb5-admin-server<Β 1.7dfsg~beta3-1ubuntu0.1UNKNOWN
Ubuntu9.10noarchkrb5-clients<Β 1.7dfsg~beta3-1ubuntu0.1UNKNOWN
Ubuntu9.10noarchkrb5-ftpd<Β 1.7dfsg~beta3-1ubuntu0.1UNKNOWN
Ubuntu9.10noarchkrb5-kdc-ldap<Β 1.7dfsg~beta3-1ubuntu0.1UNKNOWN
Ubuntu9.10noarchkrb5-pkinit<Β 1.7dfsg~beta3-1ubuntu0.1UNKNOWN
Ubuntu9.10noarchkrb5-rsh-server<Β 1.7dfsg~beta3-1ubuntu0.1UNKNOWN
Ubuntu9.10noarchkrb5-telnetd<Β 1.7dfsg~beta3-1ubuntu0.1UNKNOWN
Ubuntu9.10noarchkrb5-user<Β 1.7dfsg~beta3-1ubuntu0.1UNKNOWN
Ubuntu9.10noarchlibgssapi-krb5-2<Β 1.7dfsg~beta3-1ubuntu0.1UNKNOWN
Rows per page:
1-10 of 191

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.5

Confidence

High

EPSS

0.895

Percentile

98.8%