CVE-2021-36222

Description

ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
8.014

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Mysql 8.0.26Windows
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Insight 2.3Windows
Multiple Vulnerabilities are affected in Netapp Snapcenter 2.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Workflow Automation 2.3Windows
(RHSA-2021:3576) krb5 security update krb5-debugsource-1.18.2-8.3.el8_4.i686.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-debugsource-1.18.2-8.3.el8_4.x86_64.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-devel-1.18.2-8.3.el8_4.i686.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-devel-1.18.2-8.3.el8_4.x86_64.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-libs-1.18.2-8.3.el8_4.i686.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-libs-1.18.2-8.3.el8_4.x86_64.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-pkinit-1.18.2-8.3.el8_4.i686.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-pkinit-1.18.2-8.3.el8_4.x86_64.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-server-1.18.2-8.3.el8_4.i686.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-server-1.18.2-8.3.el8_4.x86_64.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-server-ldap-1.18.2-8.3.el8_4.i686.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-server-ldap-1.18.2-8.3.el8_4.x86_64.rpmLinux
(RHSA-2021:3576) krb5 security update krb5-workstation-1.18.2-8.3.el8_4.x86_64.rpmLinux
(RHSA-2021:3576) krb5 security update libkadm5-1.18.2-8.3.el8_4.i686.rpmLinux
(RHSA-2021:3576) krb5 security update libkadm5-1.18.2-8.3.el8_4.x86_64.rpmLinux
Krb5-devel update (ELSA-2021-3576) krb5-devel-1.18.2-8.3.el8_4.i686.rpmLinux
Krb5-devel update (ELSA-2021-3576) krb5-devel-1.18.2-8.3.el8_4.x86_64.rpmLinux
Krb5-libs update (ELSA-2021-3576) krb5-libs-1.18.2-8.3.el8_4.i686.rpmLinux
Krb5-libs update (ELSA-2021-3576) krb5-libs-1.18.2-8.3.el8_4.x86_64.rpmLinux
Krb5-pkinit update (ELSA-2021-3576) krb5-pkinit-1.18.2-8.3.el8_4.i686.rpmLinux
Krb5-pkinit update (ELSA-2021-3576) krb5-pkinit-1.18.2-8.3.el8_4.x86_64.rpmLinux
Krb5-server update (ELSA-2021-3576) krb5-server-1.18.2-8.3.el8_4.i686.rpmLinux
Krb5-server update (ELSA-2021-3576) krb5-server-1.18.2-8.3.el8_4.x86_64.rpmLinux
Krb5-server-ldap update (ELSA-2021-3576) krb5-server-ldap-1.18.2-8.3.el8_4.i686.rpmLinux
Krb5-server-ldap update (ELSA-2021-3576) krb5-server-ldap-1.18.2-8.3.el8_4.x86_64.rpmLinux
Krb5-workstation update (ELSA-2021-3576) krb5-workstation-1.18.2-8.3.el8_4.x86_64.rpmLinux
Libkadm5 update (ELSA-2021-3576) libkadm5-1.18.2-8.3.el8_4.i686.rpmLinux
Libkadm5 update (ELSA-2021-3576) libkadm5-1.18.2-8.3.el8_4.x86_64.rpmLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-kdc_1.16-2ubuntu0.4_i386.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-kdc_1.16-2ubuntu0.4_amd64.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-kdc_1.17-6ubuntu4.3_i386.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-kdc_1.17-6ubuntu4.3_amd64.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-k5tls_1.16-2ubuntu0.4_i386.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-k5tls_1.16-2ubuntu0.4_amd64.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-k5tls_1.17-6ubuntu4.3_i386.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-k5tls_1.17-6ubuntu4.3_amd64.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-pkinit_1.16-2ubuntu0.4_i386.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-pkinit_1.16-2ubuntu0.4_amd64.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-pkinit_1.17-6ubuntu4.3_i386.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-pkinit_1.17-6ubuntu4.3_amd64.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-kdc-ldap_1.16-2ubuntu0.4_i386.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-kdc-ldap_1.16-2ubuntu0.4_amd64.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-kdc-ldap_1.17-6ubuntu4.3_i386.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-kdc-ldap_1.17-6ubuntu4.3_amd64.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-k5tls_1.17-6ubuntu4.3_i386.debLinux
MIT Kerberos Network Authentication Protocol (USN-5959-1) krb5-k5tls_1.17-6ubuntu4.3_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234