MIT Kerberos 5 setup_server_realm() Remote DoS

medium Nessus Plugin ID 70941

Synopsis

A single sign-on service is affected by a denial of service vulnerability.

Description

The Kerberos service running on the remote host is affected by a remote denial of service (DoS) vulnerability. Attackers can exploit this issue to crash the affected KDC service, resulting in DoS conditions.

Solution

Update the affected krb5 package.

See Also

http://krbdev.mit.edu/rt/Ticket/Display.html?id=7757

Plugin Details

Severity: Medium

ID: 70941

File Name: mit_kerberos_cve-2013-1418.nasl

Version: 1.5

Type: remote

Family: General

Published: 11/18/2013

Updated: 7/14/2018

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Temporal Vector: E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:mit:kerberos:5

Exploit Ease: No known exploits are available

Patch Publication Date: 11/5/2013

Reference Information

CVE: CVE-2013-1418

BID: 63555