CVE-2023-36054

lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21:-:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21:beta1:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:*
cpe:2.3:a:netapp:hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*

History

15 Nov 2023, 03:23

Type Values Removed Values Added
First Time Netapp active Iq Unified Manager
Netapp clustered Data Ontap
Netapp ontap Tools
Netapp hci
Netapp management Services For Element Software
Debian
Debian debian Linux
Netapp
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:*
References (CONFIRM) https://security.netapp.com/advisory/ntap-20230908-0004/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20230908-0004/ - Third Party Advisory
References (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html - (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html - Mailing List, Third Party Advisory

22 Oct 2023, 23:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html -

08 Sep 2023, 17:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20230908-0004/ -

15 Aug 2023, 17:57

Type Values Removed Values Added
CWE CWE-824
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:mit:kerberos_5:1.21:-:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21:beta1:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*
First Time Mit
Mit kerberos 5
References (MISC) https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final - (MISC) https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final - Patch
References (MISC) https://web.mit.edu/kerberos/www/advisories/ - (MISC) https://web.mit.edu/kerberos/www/advisories/ - Product
References (CONFIRM) https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd - (CONFIRM) https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd - Patch
References (MISC) https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final - (MISC) https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final - Patch

07 Aug 2023, 19:30

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-07 19:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-36054

Mitre link : CVE-2023-36054

CVE.ORG link : CVE-2023-36054


JSON object : View

Products Affected

debian

  • debian_linux

netapp

  • hci
  • ontap_tools
  • active_iq_unified_manager
  • clustered_data_ontap
  • management_services_for_element_software

mit

  • kerberos_5
CWE
CWE-824

Access of Uninitialized Pointer