Candidate: CVE-2017-11368 PublicDate: 2017-08-09 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11368 https://github.com/krb5/krb5/pull/678/files Description: In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests. Ubuntu-Description: It was discovered that Kerberos incorrectly handled certain S4U2Self or S4U2Proxy requests. A remote authenticated attacker could possibly use this issue to cause a denial of service. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=869260 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_krb5: upstream: https://github.com/krb5/krb5/pull/678/commits/a860385dd8fbd239fdb31b347e07f4e6b2fbdcc2 Tags_krb5: universe-binary upstream_krb5: released (1.15.1-2) precise/esm_krb5: ignored (end of ESM support, was needed) trusty_krb5: released (1.12+dfsg-2ubuntu5.4) trusty/esm_krb5: released (1.12+dfsg-2ubuntu5.4) vivid/ubuntu-core_krb5: ignored (reached end-of-life) xenial_krb5: released (1.13.2+dfsg-5ubuntu2.1) esm-infra/xenial_krb5: released (1.13.2+dfsg-5ubuntu2.1) zesty_krb5: ignored (reached end-of-life) artful_krb5: not-affected (1.15.1-2) bionic_krb5: not-affected (1.15.1-2) cosmic_krb5: not-affected (1.15.1-2) disco_krb5: not-affected (1.15.1-2) eoan_krb5: not-affected (1.15.1-2) focal_krb5: not-affected (1.15.1-2) groovy_krb5: not-affected (1.15.1-2) hirsute_krb5: not-affected (1.15.1-2) devel_krb5: not-affected (1.15.1-2)