CVE-2017-7562
26.07.2018, 15:29
An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and erroneous circumstances.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| mit | kerberos_5 | 1.0 ≤ 𝑥 < 1.16.1 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||
|---|---|---|---|---|---|
| krb5 |
| ||||
| krb5-32bit |
| ||||
| krb5-client |
| ||||
| krb5-doc |
| ||||
| krb5-plugin-kdb-ldap |
| ||||
| krb5-plugin-preauth-otp |
| ||||
| krb5-plugin-preauth-pkinit |
| ||||
| krb5-server |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References