CVE-2017-15088 -- krb5-kdcID: oval:org.secpod.oval:def:1900289 | Date: (C)2019-06-03 (M)2023-12-20 |
Class: VULNERABILITY | Family: unix |
plugins/preauth/pkinit/pkinit_crypto_opelibnss3-devl.c in MIT Kerberos 5 through 1.15.2 mishandles Distinguished Name fields, which allow sremote attackers to execute arbitrary code or cause a denial of service in situations involving untrustedX.509 data, related to the get_matching_data and X509_NAME_one line_exfunctions. NOTE: this has security relevance only in use cases outside of the MIT Kerberos distribution, e.g., the use of get_matching_data in KDCcertauth plugin code that is specific to Red Hat.
Platform: |
Ubuntu 16.04 |
Ubuntu 14.04 |