CVE-2015-8629

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string.

References

http://krbdev.mit.edu/rt/Ticket/Display.html?id=8341

http://lists.opensuse.org/opensuse-updates/2016-02/msg00059.html

http://lists.opensuse.org/opensuse-updates/2016-02/msg00110.html

http://rhn.redhat.com/errata/RHSA-2016-0493.html

http://rhn.redhat.com/errata/RHSA-2016-0532.html

http://www.debian.org/security/2016/dsa-3466

http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html

http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html

http://www.securityfocus.com/bid/82801

http://www.securitytracker.com/id/1034914

https://github.com/krb5/krb5/commit/df17a1224a3406f57477bcd372c61e04c0e5a5bb

Details

Source: MITRE

Published: 2016-02-13

Updated: 2021-02-02

Type: CWE-125

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1.6

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*

cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:o:oracle:linux:6:-:*:*:*:*:*:*

cpe:2.3:o:oracle:linux:7:-:*:*:*:*:*:*

cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*

cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*

Configuration 3

OR

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 4

OR

cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*

cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

Configuration 5

OR

cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:6.7:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.2:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.3:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.2:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

Tenable Plugins

View all (17 total)

IDNameProductFamilySeverity
99775EulerOS 2.0 SP1 : krb5 (EulerOS-SA-2016-1012)NessusHuawei Local Security Checks
high
90633Amazon Linux AMI : krb5 (ALAS-2016-691)NessusAmazon Linux Local Security Checks
high
90344Scientific Linux Security Update : krb5 on SL7.x x86_64 (20160404)NessusScientific Linux Local Security Checks
high
90299RHEL 7 : krb5 (RHSA-2016:0532)NessusRed Hat Local Security Checks
high
90295Oracle Linux 7 : krb5 (ELSA-2016-0532)NessusOracle Linux Local Security Checks
high
90275CentOS 7 : krb5 (CESA-2016:0532)NessusCentOS Local Security Checks
high
90145Scientific Linux Security Update : krb5 on SL6.x i386/x86_64 (20160323)NessusScientific Linux Local Security Checks
medium
90138OracleVM 3.3 / 3.4 : krb5 (OVMSA-2016-0039)NessusOracleVM Local Security Checks
medium
90122CentOS 6 : krb5 (CESA-2016:0493)NessusCentOS Local Security Checks
medium
90116RHEL 6 : krb5 (RHSA-2016:0493)NessusRed Hat Local Security Checks
medium
90112Oracle Linux 6 : krb5 (ELSA-2016-0493)NessusOracle Linux Local Security Checks
medium
88886Debian DLA-423-1 : krb5 security updateNessusDebian Local Security Checks
medium
88854openSUSE Security Update : krb5 (openSUSE-2016-230)NessusSuSE Local Security Checks
high
88708SUSE SLED11 / SLES11 Security Update : krb5 (SUSE-SU-2016:0430-1)NessusSuSE Local Security Checks
medium
88707SUSE SLED12 / SLES12 Security Update : krb5 (SUSE-SU-2016:0429-1)NessusSuSE Local Security Checks
high
88687openSUSE Security Update : krb5 (openSUSE-2016-181)NessusSuSE Local Security Checks
high
88581Debian DSA-3466-1 : krb5 - security updateNessusDebian Local Security Checks
high