Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-2694
HistoryMay 25, 2015 - 12:00 a.m.

CVE-2015-2694

2015-05-2500:00:00
ubuntu.com
ubuntu.com
11

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS

0.004

Percentile

74.6%

The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x
before 1.13.2 do not properly track whether a client’s request has been
validated, which allows remote attackers to bypass an intended
preauthentication requirement by providing (1) zero bytes of data or (2) an
arbitrary realm name, related to plugins/preauth/otp/main.c and
plugins/preauth/pkinit/pkinit_srv.c.

Bugs

Notes

Author Note
tyhicks affects 1.12 and later
OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchkrb5< 1.12+dfsg-2ubuntu5.2UNKNOWN
ubuntu15.04noarchkrb5< 1.12.1+dfsg-18ubuntu0.1UNKNOWN

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS

0.004

Percentile

74.6%