CVE-2018-20217

LOW

Description

A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DES, triple-DES, or RC4), the attacker can crash the KDC by making an S4U2Self request.

References

http://krbdev.mit.edu/rt/Ticket/Display.html?id=8763

https://github.com/krb5/krb5/commit/5e6d1796106df8ba6bc1973ee0917c170d929086

https://lists.debian.org/debian-lts-announce/2019/01/msg00020.html

https://lists.fedoraproject.org/archives/list/[email protected]/message/2KNHELH4YHNT6H2ESJWX2UIDXLBNGB2O/

https://security.netapp.com/advisory/ntap-20190416-0006/

Details

Source: MITRE

Published: 2018-12-26

Updated: 2019-10-03

Type: CWE-617

Risk Information

CVSS v2.0

Base Score: 3.5

Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 6.8

Severity: LOW

CVSS v3.0

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.6

Severity: MEDIUM