CVE-2015-8630: Null Pointer Dereference
The (1) kadm5createprincipal3 and (2) kadm5modifyprincipal functions in lib/kadm5/srv/svrprincipal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by specifying KADM5POLICY with a NULL policy name.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8630?
CVE-2015-8630 is classified as a denial of service vulnerability.
How do I fix CVE-2015-8630?
To resolve CVE-2015-8630, upgrade to MIT Kerberos 5 version 1.13.4 or later for 1.13.x series, or 1.14.1 or later for 1.14.x series.
What systems are affected by CVE-2015-8630?
CVE-2015-8630 affects MIT Kerberos 5 versions 1.12.x, 1.13.x before 1.13.4, and 1.14.x before 1.14.1.
Can remote users exploit CVE-2015-8630?
Yes, remote authenticated users can exploit CVE-2015-8630 to cause a denial of service.
What type of issues does CVE-2015-8630 cause?
CVE-2015-8630 causes a denial of service due to NULL pointer dereference.