Back to search
CVE-2015-2694
Published: May 25, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1) zero bytes of data or (2) an arbitrary realm name, related to plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit_srv.c.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/krb5/krb5/commit/e3b5a5e5267818c97750b266df50b6a3d4649604
x_refsource_CONFIRM
74824
vdb-entry
x_refsource_BID
http://krbdev.mit.edu/rt/Ticket/Display.html?id=8160
x_refsource_CONFIRM
USN-2810-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now