CVE-2015-2696: High severity kerberos vulnerability
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gssinquirecontext call.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2696?
CVE-2015-2696 has been classified as a medium severity vulnerability.
How do I fix CVE-2015-2696?
To fix CVE-2015-2696, update your MIT Kerberos 5 installation to version 1.14 or later.
What types of systems are affected by CVE-2015-2696?
CVE-2015-2696 affects MIT Kerberos 5 before version 1.14 and specific versions of openSUSE, SUSE Linux Enterprise, and Debian.
What impact does CVE-2015-2696 have on systems?
CVE-2015-2696 can cause a denial of service by crashing the process due to mishandled IAKERB packets.
Is there a workaround for CVE-2015-2696?
There are no effective workarounds for CVE-2015-2696; the best action is to apply the relevant updates.