CVE-2015-8631

Impact:
Moderate
Public Date:
2016-01-08
CWE:
CWE-401
Bugzilla:
1302642: CVE-2015-8631 krb5: Memory leak caused by supplying a null principal name in request
A memory leak flaw was found in the krb5_unparse_name() function of the MIT Kerberos kadmind service. An authenticated attacker could repeatedly send specially crafted requests to the server, which could cause the server to consume large amounts of memory resources, ultimately leading to a denial of service due to memory exhaustion.

Find out more about CVE-2015-8631 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4
Base Metrics AV:N/AC:L/Au:S/C:N/I:N/A:P
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (krb5) RHSA-2016:0532 2016-03-31
Red Hat Enterprise Linux 6 (krb5) RHSA-2016:0493 2016-03-22

Affected Packages State

Platform Package State
Red Hat JBoss EWS 2 krb5 Not affected
Red Hat Enterprise Linux 5 krb5 Will not fix

Acknowledgements

This issue was discovered by Simo Sorce of Red Hat.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.