Candidate: CVE-2015-3206 PublicDate: 2017-08-25 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3206 Description: The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/bugs/1716429 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_pykerberos: upstream_pykerberos: released (1.1.6) precise_pykerberos: released (1.1+svn4895-1+deb6u1build0.12.04.1) precise/esm_pykerberos: DNE (precise was released [1.1+svn4895-1+deb6u1build0.12.04.1]) trusty_pykerberos: ignored (reached end-of-life) trusty/esm_pykerberos: DNE (trusty was needed) utopic_pykerberos: ignored (reached end-of-life) vivid_pykerberos: ignored (reached end-of-life) vivid/stable-phone-overlay_pykerberos: DNE vivid/ubuntu-core_pykerberos: DNE wily_pykerberos: ignored (reached end-of-life) xenial_pykerberos: not-affected (1.1.5-2build1) yakkety_pykerberos: ignored (reached end-of-life) zesty_pykerberos: not-affected (1.1.5-2build1) artful_pykerberos: not-affected (1.1.5-2build3) bionic_pykerberos: not-affected (1.1.5-2build3) cosmic_pykerberos: not-affected (1.1.5-2build3) disco_pykerberos: not-affected (1.1.5-2build3) devel_pykerberos: not-affected (1.1.5-2build3)