CVE-2023-36054
NetApp ActiveIQ Unified Manager: Sicherheitsluecke
noneEPSS 2.8%
Affected
- Dell/ECS
3.8.1.1..* - MIT/Kerberos
1.20.2..* - MIT/Kerberos
1.21.1..* - NetApp/ActiveIQ Unified Manager
for VMware vSphere..* - Xerox/FreeFlow Print Server
v7..* - Xerox/FreeFlow Print Server
v9..*
Description
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
Source: BSI CSAFBSI WID Portalcvelistv5
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
DellECS
3.8.1.1MITKerberos
1.20.21.21.1NetAppActiveIQ Unified Manager
for VMware vSphereXeroxFreeFlow Print Server
v7v9Metrics
86.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
none
62.66
no public PoC known
Published
2023-08-07 00:00 UTC
References & sources
- https://web.mit.edu/kerberos/www/advisories/
- https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final
- https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final
- https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd
- https://security.netapp.com/advisory/ntap-20230908-0004/
- https://lists.debian.org/debian-lts-announce/2023/10/msg00031.htmlmailing-list