First published: Thu Sep 26 2019(Updated: )
A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
MIT Kerberos 5 | >=1.16.1<=1.17.1 | |
Fedora | =29 | |
Fedora | =30 | |
Fedora | =31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14844 is a vulnerability found in Fedora versions of krb5 from 1.16.1 to including 1.17.x.
CVE-2019-14844 can crash the KDC if a remote unauthenticated user sends one of the RFC 4556 "enctypes".
CVE-2019-14844 affects Fedora versions 29, 30, and 31, as well as MIT Kerberos 5 versions from 1.16.1 to including 1.17.x.
CVE-2019-14844 has a severity rating of 7.5 (high).
To fix CVE-2019-14844, update to a version of krb5 that is not vulnerable.