CVE-2023-36054

lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mit:kerberos_5:1.21:beta1:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21:-:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:*

History

15 Nov 2023, 03:23

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
References (CONFIRM) https://security.netapp.com/advisory/ntap-20230908-0004/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20230908-0004/ - Third Party Advisory
References (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html - (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html - Mailing List, Third Party Advisory
First Time Netapp active Iq Unified Manager
Netapp hci
Debian
Netapp clustered Data Ontap
Netapp management Services For Element Software
Netapp ontap Tools
Debian debian Linux
Netapp

22 Oct 2023, 23:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20230908-0004/ -
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html -

15 Aug 2023, 17:57

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Mit kerberos 5
Mit
CPE cpe:2.3:a:mit:kerberos_5:1.21:-:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21:beta1:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*
CWE CWE-824
References (MISC) https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final - (MISC) https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final - Patch
References (MISC) https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final - (MISC) https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final - Patch
References (MISC) https://web.mit.edu/kerberos/www/advisories/ - (MISC) https://web.mit.edu/kerberos/www/advisories/ - Product
References (CONFIRM) https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd - (CONFIRM) https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd - Patch

07 Aug 2023, 19:30

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-07 19:15

Updated : 2023-11-15 03:23


NVD link : CVE-2023-36054

Mitre link : CVE-2023-36054


JSON object : View

Products Affected

debian

  • debian_linux

netapp

  • hci
  • management_services_for_element_software
  • clustered_data_ontap
  • active_iq_unified_manager
  • ontap_tools

mit

  • kerberos_5
CWE
CWE-824

Access of Uninitialized Pointer