From 3178b9c630b8092f535baeaab6962f63fe2ce7e1 Mon Sep 17 00:00:00 2001 From: cy Date: Fri, 22 Jul 2016 00:22:18 +0000 Subject: Document a rare KDC denial of service vulnerability when anonymous client principals are restricted to obtaining TGTs only [CVE-2016-3120] URL: http://web.mit.edu/kerberos/krb5-1.14/ Security: CVE-2016-3120 --- security/vuxml/vuln.xml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index b97f470dd83..a70d1be6c45 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,34 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + krb5 -- KDC denial of service vulnerability + + + krb5-114 + 1.14.3 + + + + +

Major changes in krb5 1.14.3:

+
+

Fix a rare KDC denial of service vulnerability when anonymous + client principals are restricted to obtaining TGTs only + [CVE-2016-3120] .

+
+ +
+ + CVE-2016-3120 + http://web.mit.edu/kerberos/krb5-1.14/ + + + 2016-07-20 + 2016-07-21 + +
+ Apache OpenOffice 4.1.2 -- Memory Corruption Vulnerability (Impress Presentations) -- cgit