Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 636180 (CVE-2016-3120) - <app-crypt/mit-krb5-1.15.2: Denial of Service (CVE-2016-3120)
Summary: <app-crypt/mit-krb5-1.15.2: Denial of Service (CVE-2016-3120)
Status: RESOLVED FIXED
Alias: CVE-2016-3120
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://web.mit.edu/kerberos/krb5-1.14/
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-11-01 18:44 UTC by GLSAMaker/CVETool Bot
Modified: 2017-11-23 23:21 UTC (History)
1 user (show)

See Also:
Package list:
=app-crypt/mit-krb5-1.15.2
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-11-01 18:44:32 UTC
CVE-2016-3120 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3120):
  The validate_as_request function in kdc_util.c in the Key Distribution
  Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before
  1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client
  data structure, which allows remote authenticated users to cause a denial of
  service (NULL pointer dereference and daemon crash) via an S4U2Self request.
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-01 18:45:40 UTC
@Maintainers we have 1.14.3 in tree which is fixed, please call for stabilization when ready.

Thank you
Comment 2 Eray Aslan gentoo-dev 2017-11-06 07:52:54 UTC
Arches, please test and mark stable
=app-crypt/mit-krb5-1.15.2

Target Keywords = alpha amd64 arm ~arm64 hppa ia64 ~mips ppc ppc64 ~s390 ~sh ~sparc x86

Thank you
Comment 3 Sergei Trofimovich (RETIRED) gentoo-dev 2017-11-06 10:02:23 UTC
ia64 stable
Comment 4 Tobias Klausmann (RETIRED) gentoo-dev 2017-11-06 14:18:45 UTC
Stable on alpha.
Comment 5 Agostino Sarubbo gentoo-dev 2017-11-08 13:39:19 UTC
amd64 stable
Comment 6 Sergei Trofimovich (RETIRED) gentoo-dev 2017-11-11 12:02:04 UTC
ppc/ppc64 stable
Comment 7 Sergei Trofimovich (RETIRED) gentoo-dev 2017-11-11 22:29:57 UTC
hppa stable
Comment 8 Thomas Deutschmann (RETIRED) gentoo-dev 2017-11-14 21:45:08 UTC
x86 stable (ignoring test failures from bug 637526).
Comment 9 Markus Meier gentoo-dev 2017-11-19 15:12:17 UTC
arm stable, all arches done.
Comment 10 Aaron Bauman (RETIRED) gentoo-dev 2017-11-19 17:54:05 UTC
@maintainer(s), please clean the vulnerable versions.
Comment 11 Eray Aslan gentoo-dev 2017-11-20 08:08:44 UTC
cleanup done
Comment 12 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-20 13:38:22 UTC
(In reply to Eray Aslan from comment #11)
> cleanup done

Thank you. Closing report.
Comment 13 Rolf Eike Beer archtester 2017-11-23 16:55:58 UTC
tatt says it looks good on sparc
Comment 14 Sergei Trofimovich (RETIRED) gentoo-dev 2017-11-23 23:21:19 UTC
sparc stable (thanks to Rolf Eike Beer)