CVE-2017-15088 Detail
Current Description
plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) in situations involving untrusted X.509 data, related to the get_matching_data and X509_NAME_oneline_ex functions. NOTE: this has security relevance only in use cases outside of the MIT Kerberos distribution, e.g., the use of get_matching_data in KDC certauth plugin code that is specific to Red Hat.
Source:
MITRE
Description Last Modified:
11/23/2017
View Analysis Description
Analysis Description
plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) in situations involving untrusted X.509 data, related to the get_matching_data and X509_NAME_oneline_ex functions. NOTE: this has security relevance only in use cases outside of the MIT Kerberos distribution, e.g., the use of get_matching_data in KDC certauth plugin code that is specific to Red Hat.
Source:
MITRE
Description Last Modified:
11/23/2017
Impact
CVSS v3.0 Severity and Metrics:
Base Score:
9.8 CRITICAL
Vector:
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
(V3 legend)
Impact Score:
5.9
Exploitability Score:
3.9
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High
CVSS v2.0 Severity and Metrics:
Base Score:
7.5 HIGH
Vector:
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
(V2 legend)
Impact Subscore:
6.4
Exploitability Subscore:
10.0
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (AU):
None
Confidentiality (C):
Partial
Integrity (I):
Partial
Availability (A):
Partial
Additional Information:
Allows unauthorized disclosure of information Allows unauthorized modification Allows disruption of service
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because
they may have information that would be of interest to you. No inferences should be drawn on account of other sites
being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.
NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further,
NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about
this page to nvd@nist.gov.
Change History
2 change records found
- show changes
Initial Analysis -
12/12/2017 1:05:37 PM
| Action |
Type |
Old Value |
New Value |
| Added |
CPE Configuration |
|
OR
*cpe:2.3:a:mit:kerberos:*:*:*:*:*:*:*:* versions up to (including) 5-1.15.2 |
| Added |
CVSS V2 |
|
(AV:N/AC:L/Au:N/C:P/I:P/A:P) |
| Added |
CVSS V3 |
|
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Added |
CWE |
|
CWE-119 |
| Changed |
Reference Type |
http://www.securityfocus.com/bid/101594 No Types Assigned |
http://www.securityfocus.com/bid/101594 Third Party Advisory, VDB Entry |
| Changed |
Reference Type |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=871698 No Types Assigned |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=871698 Issue Tracking, Third Party Advisory |
| Changed |
Reference Type |
https://bugzilla.redhat.com/show_bug.cgi?id=1504045 No Types Assigned |
https://bugzilla.redhat.com/show_bug.cgi?id=1504045 Issue Tracking, Patch, Third Party Advisory |
| Changed |
Reference Type |
https://github.com/krb5/krb5/commit/fbb687db1088ddd894d975996e5f6a4252b9a2b4 No Types Assigned |
https://github.com/krb5/krb5/commit/fbb687db1088ddd894d975996e5f6a4252b9a2b4 Issue Tracking, Patch, Third Party Advisory |
| Changed |
Reference Type |
https://github.com/krb5/krb5/pull/707 No Types Assigned |
https://github.com/krb5/krb5/pull/707 Issue Tracking, Third Party Advisory |
CVE Modified by MITRE -
11/24/2017 9:29:01 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
|
http://www.securityfocus.com/bid/101594 [No Types Assigned] |
Quick Info
CVE Dictionary Entry:
CVE-2017-15088
NVD Published Date:
11/23/2017
NVD Last Modified:
12/12/2017
|