CVE-2017-7562

An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and erroneous circumstances.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
redhatenterprise_linux
7.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
7.0
mitkerberos_5
1.0 ≤
𝑥
< 1.16.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
krb5
bookworm
1.20.1-2+deb12u2
fixed
bookworm (security)
1.20.1-2+deb12u2
fixed
bullseye
1.18.3-6+deb11u5
fixed
bullseye (security)
1.18.3-6+deb11u5
fixed
sid
1.21.3-3
fixed
trixie
1.21.3-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
krb5
trusty
not-affected
xenial
not-affected
zesty
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
krb5
suse enterprise server 12
1.12.1-38.5.3
fixed
suse enterprise server 12 SP1
1.12.1-38.5.3
fixed
krb5-32bit
suse enterprise server 12
1.12.1-38.5.3
fixed
suse enterprise server 12 SP1
1.12.1-38.5.3
fixed
krb5-client
suse enterprise server 12
1.12.1-38.5.3
fixed
suse enterprise server 12 SP1
1.12.1-38.5.3
fixed
krb5-doc
suse enterprise server 12
1.12.1-38.5.3
fixed
suse enterprise server 12 SP1
1.12.1-38.5.3
fixed
krb5-plugin-kdb-ldap
suse enterprise server 12
1.12.1-38.5.3
fixed
suse enterprise server 12 SP1
1.12.1-38.5.3
fixed
krb5-plugin-preauth-otp
suse enterprise server 12
1.12.1-38.5.3
fixed
suse enterprise server 12 SP1
1.12.1-38.5.3
fixed
krb5-plugin-preauth-pkinit
suse enterprise server 12
1.12.1-38.5.3
fixed
suse enterprise server 12 SP1
1.12.1-38.5.3
fixed
krb5-server
suse enterprise server 12
1.12.1-38.5.3
fixed
suse enterprise server 12 SP1
1.12.1-38.5.3
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
krb5-devel
RHEL 7
0:1.15.1-18.el7
fixed
krb5-libs
RHEL 7
0:1.15.1-18.el7
fixed
krb5-pkinit
RHEL 7
0:1.15.1-18.el7
fixed
krb5-server
RHEL 7
0:1.15.1-18.el7
fixed
krb5-server-ldap
RHEL 7
0:1.15.1-18.el7
fixed
krb5-workstation
RHEL 7
0:1.15.1-18.el7
fixed
libkadm5
RHEL 7
0:1.15.1-18.el7
fixed