Candidate: CVE-2015-8630 PublicDate: 2016-02-13 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8630 Description: The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by specifying KADM5_POLICY with a NULL policy name. Ubuntu-Description: It was discovered that Kerberos incorrectly handled policy names. A remote authenticated attacker could possibly use this issue to cause a denial of service. Notes: mdeslaur> introduced in 1.12 ratliff> use of kadmind is not supported in touch and core Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=813127 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_krb5: upstream: https://github.com/krb5/krb5/commit/b863de7fbf080b15e347a736fdda0a82d42f4f6b Tags_krb5: universe-binary upstream_krb5: released (1.14+dfsg-1) precise_krb5: not-affected (1.10+dfsg~beta1-2ubuntu0.7) precise/esm_krb5: not-affected (1.10+dfsg~beta1-2ubuntu0.7) trusty_krb5: released (1.12+dfsg-2ubuntu5.4) trusty/esm_krb5: released (1.12+dfsg-2ubuntu5.4) vivid_krb5: ignored (reached end-of-life) vivid/stable-phone-overlay_krb5: ignored vivid/ubuntu-core_krb5: ignored wily_krb5: ignored (reached end-of-life) xenial_krb5: not-affected (1.13.2+dfsg-5) esm-infra/xenial_krb5: not-affected (1.13.2+dfsg-5) yakkety_krb5: not-affected (1.14.3+dfsg-2ubuntu1) zesty_krb5: not-affected (1.14.3+dfsg-2ubuntu1) artful_krb5: not-affected (1.14.3+dfsg-2ubuntu1) bionic_krb5: not-affected (1.14.3+dfsg-2ubuntu1) cosmic_krb5: not-affected (1.14.3+dfsg-2ubuntu1) devel_krb5: not-affected (1.14.3+dfsg-2ubuntu1)