Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6167
HistoryApr 23, 2018 - 5:47 a.m.

Denial Of Service (DoS)

2018-04-2305:47:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

EPSS

0.021

Percentile

89.1%

libkrb5.so is vulnerable to denial of service (DoS) through buffer overflow attacks. The vulnerability exists in the get_matching_data() function of krb5 that includes certauth plugin, and subsequently allowing both the CA certificate and the user’s certificate to have long subjects, causing a denial of service (DoS) attack. Remarks: This attack requires a validated certificate with a long subject and issuer, and a pkinit_cert_match string attribute that matches a principal in the database.