CVE-2023-36054

NetApp ActiveIQ Unified Manager: Sicherheitsluecke

Affected

  • Dell/ECS 3.8.1.1..*
  • MIT/Kerberos 1.20.2..*
  • MIT/Kerberos 1.21.1..*
  • NetApp/ActiveIQ Unified Manager for VMware vSphere..*
  • Xerox/FreeFlow Print Server v7..*
  • Xerox/FreeFlow Print Server v9..*

Description

lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

DellECS
3.8.1.1
MITKerberos
1.20.21.21.1
NetAppActiveIQ Unified Manager
for VMware vSphere
XeroxFreeFlow Print Server
v7v9

Metrics

86.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
none
no public PoC known
2.8 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2023-08-07 00:00 UTC

References & sources