REDHAT-BUG-2342796: Medium severity mit kerberos 5 vulnerability
In MIT krb5 release 1.7 and later with incremental propagation enabled, an authenticated attacker can cause kadmind to write beyond the end of the mapped region for the iprop log file, likely causing a process crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2342796?
The severity of REDHAT-BUG-2342796 is high due to the potential for an authenticated attacker to cause a process crash.
How do I fix REDHAT-BUG-2342796?
To fix REDHAT-BUG-2342796, update your MIT krb5 installation to a version later than 1.7 that addresses this vulnerability.
What versions of MIT krb5 are affected by REDHAT-BUG-2342796?
All versions of MIT krb5 from 1.7 and later with incremental propagation enabled are affected by REDHAT-BUG-2342796.
What could be the potential impact of REDHAT-BUG-2342796?
The potential impact of REDHAT-BUG-2342796 includes crashing the kadmind process, leading to denial of service.
Who can exploit the vulnerability identified as REDHAT-BUG-2342796?
The vulnerability identified as REDHAT-BUG-2342796 can be exploited by authenticated attackers.