CVE-2017-11368: Medium severity fedoraproject fedora vulnerability
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
Other sources
It was found that in MIT krb5 1.7 and later, an authenticated attacker can cause an assertion failure in krb5kdc by sending an invalid S4U2Self or S4U2Proxy request.
Upstream patch:
https://github.com/krb5/krb5/pull/678/commits/ffb35baac698
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11368?
CVE-2017-11368 is classified as medium severity.
How do I fix CVE-2017-11368?
To fix CVE-2017-11368, it is recommended to upgrade to a patched version of MIT Kerberos 5 or apply relevant security updates from your distribution.
Which versions of MIT Kerberos are affected by CVE-2017-11368?
CVE-2017-11368 affects MIT Kerberos 5 versions 1.7 and later.
Can CVE-2017-11368 be exploited remotely?
CVE-2017-11368 can be exploited by an authenticated attacker, rather than remotely.
What kind of attack is associated with CVE-2017-11368?
CVE-2017-11368 involves sending invalid S4U2Self or S4U2Proxy requests to cause a KDC assertion failure.