Denial of service in Kerberos - CVE-2017-11368
Published: October 19, 2017
Vulnerability identifier: #VU8901
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11368
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The weakness exists due to an assertion failure. A remote attacker can send invalid S4U2Self or S4U2Proxy requests and cause the krb5kdc service to exit on a targeted system.
Successful exploitation of the vulnerability results in denial of service.
The weakness exists due to an assertion failure. A remote attacker can send invalid S4U2Self or S4U2Proxy requests and cause the krb5kdc service to exit on a targeted system.
Successful exploitation of the vulnerability results in denial of service.
Affected software
Kerberos
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Fedora
krb5
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Fedora
krb5
How to mitigate CVE-2017-11368
Update to version 1.14.6 or 1.15.2.
krb5 - addressed in versions 1.14.4-5.fc24, 1.14.4-8.fc25, 1.15.1-17.fc26