FS#45575 - [krb5] CVE-2015-2694: PKINIT requires_preauth bypass leading to possible ciphertext reconstruction
Attached to Project:
Arch Linux
Opened by Levente Polyak (anthraxx) - Monday, 06 July 2015, 22:28 GMT
Last edited by Bartłomiej Piotrowski (Barthalion) - Sunday, 12 July 2015, 17:19 GMT
Opened by Levente Polyak (anthraxx) - Monday, 06 July 2015, 22:28 GMT
Last edited by Bartłomiej Piotrowski (Barthalion) - Sunday, 12 July 2015, 17:19 GMT
|
Details
Description:
It has been reported [0][1] that krb5 before version 1.13.2 is vulnerable to an issues in OTP and PKINIT kdcpreauth modules leading to requires_preauth bypass. This issue can be used to obtain user password by performing a dictionary-attack on the retrieved ciphertext. Mitigation: Upgrade to 1.13.2 (this also fixes a minor severity issue CVE-2014-5355) [0]: http://krbdev.mit.edu/rt/NoAuth/krb5-1.13/fixed-1.13.2.html [1]: http://krbdev.mit.edu/rt/Ticket/Display.html?id=8160 |
This task depends upon
Closed by Bartłomiej Piotrowski (Barthalion)
Sunday, 12 July 2015, 17:19 GMT
Reason for closing: Fixed
Additional comments about closing: krb5 1.13.2-1
Sunday, 12 July 2015, 17:19 GMT
Reason for closing: Fixed
Additional comments about closing: krb5 1.13.2-1