CVE Vulnerabilities

CVE-2015-2694

Published: May 25, 2015 | Modified: Jan 21, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a clients request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1) zero bytes of data or (2) an arbitrary realm name, related to plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit_srv.c.

Affected Software

Name Vendor Start Version End Version
Kerberos_5 Mit 1.12 (including) 1.12 (including)
Kerberos_5 Mit 1.12.1 (including) 1.12.1 (including)
Kerberos_5 Mit 1.12.2 (including) 1.12.2 (including)
Kerberos_5 Mit 1.12.3 (including) 1.12.3 (including)
Kerberos_5 Mit 1.13 (including) 1.13 (including)
Kerberos_5 Mit 1.13.1 (including) 1.13.1 (including)

References