CVE-2023-36054

lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21:-:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21:beta1:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:*
cpe:2.3:a:netapp:hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*

History

21 Nov 2024, 08:09

Type Values Removed Values Added
References () https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd - Patch () https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd - Patch
References () https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final - Patch () https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final - Patch
References () https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final - Patch () https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final - Patch
References () https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html - Mailing List, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20230908-0004/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20230908-0004/ - Third Party Advisory
References () https://web.mit.edu/kerberos/www/advisories/ - Product () https://web.mit.edu/kerberos/www/advisories/ - Product

15 Nov 2023, 03:23

Type Values Removed Values Added
First Time Debian debian Linux
Netapp
Netapp hci
Debian
Netapp active Iq Unified Manager
Netapp management Services For Element Software
Netapp ontap Tools
Netapp clustered Data Ontap
CPE cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:*
References (CONFIRM) https://security.netapp.com/advisory/ntap-20230908-0004/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20230908-0004/ - Third Party Advisory
References (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html - (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html - Mailing List, Third Party Advisory

22 Oct 2023, 23:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html -

08 Sep 2023, 17:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20230908-0004/ -

15 Aug 2023, 17:57

Type Values Removed Values Added
First Time Mit
Mit kerberos 5
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21:beta1:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21:-:*:*:*:*:*:*
CWE CWE-824
References (MISC) https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final - (MISC) https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final - Patch
References (CONFIRM) https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd - (CONFIRM) https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd - Patch
References (MISC) https://web.mit.edu/kerberos/www/advisories/ - (MISC) https://web.mit.edu/kerberos/www/advisories/ - Product
References (MISC) https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final - (MISC) https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final - Patch

07 Aug 2023, 19:30

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-07 19:15

Updated : 2024-11-21 08:09


NVD link : CVE-2023-36054

Mitre link : CVE-2023-36054

CVE.ORG link : CVE-2023-36054


JSON object : View

Products Affected

debian

  • debian_linux

netapp

  • active_iq_unified_manager
  • ontap_tools
  • clustered_data_ontap
  • hci
  • management_services_for_element_software

mit

  • kerberos_5
CWE
CWE-824

Access of Uninitialized Pointer