Vulnerability Name:

CVE-2013-1416 (CCN-83634)

Assigned:2013-03-29
Published:2013-03-29
Updated:2021-02-02
Summary:The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS-REQ request.
CVSS v3 Severity:4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
6.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:C/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
4.0 Medium (REDHAT CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
3.5 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-476
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2013-1416

Source: CONFIRM
Type: Vendor Advisory
http://krbdev.mit.edu/rt/Ticket/Display.html?id=7600

Source: CCN
Type: Kerberos Ticket #7600
KDC TGS-REQ null deref

Source: FEDORA
Type: Third Party Advisory
FEDORA-2013-5280

Source: FEDORA
Type: Third Party Advisory
FEDORA-2013-5286

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2013:0746

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2013:0904

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2013:0967

Source: REDHAT
Type: Third Party Advisory
RHSA-2013:0748

Source: CCN
Type: SA53104
Kerberos KDC TGS-REQ Processing NULL-Pointer Dereference Denial of Service Vulnerability

Source: CCN
Type: MIT Kerberos Web Site
Kerberos: The Network Authentication Protocol

Source: MANDRIVA
Type: Third Party Advisory
MDVSA-2013:157

Source: MANDRIVA
Type: Third Party Advisory
MDVSA-2013:158

Source: CCN
Type: BID-59261
MIT Kerberos CVE-2013-1416 NULL Pointer Dereference Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
kerberos-prepreprocessreq-dos(83634)

Source: CCN
Type: MIT Kerberos GIT Repository Web Site
MIT Kerberos GIT Repository

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/krb5/krb5/commit/8ee70ec63931d1e38567905387ab9b1d45734d81

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mit:kerberos_5:*:*:*:*:*:*:*:* (Version < 1.10.5)

  • Configuration 2:
  • cpe:/o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:12.3:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:17:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:18:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_eus:6.4:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20131416
    V
    CVE-2013-1416
    2022-05-20
    oval:org.opensuse.security:def:30289
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:33117
    P
    Security update for openexr (Important)
    2022-01-12
    oval:org.opensuse.security:def:33060
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:33739
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:33971
    P
    Security update for openssl-1_0_0 (Low)
    2021-09-09
    oval:org.opensuse.security:def:30234
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:33949
    P
    Security update for qemu (Important)
    2021-07-28
    oval:org.opensuse.security:def:34489
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:30081
    P
    Security update for qemu (Important)
    2021-06-02
    oval:org.opensuse.security:def:33910
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:33645
    P
    Security update for samba (Important)
    2021-05-04
    oval:org.opensuse.security:def:33644
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:34420
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:32904
    P
    Security update for MozillaFirefox (Important)
    2021-04-27
    oval:org.opensuse.security:def:34028
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:33656
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:34445
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:28868
    P
    Security update for python (Important)
    2020-12-11
    oval:org.opensuse.security:def:34332
    P
    Security update for curl (Moderate)
    2020-12-10
    oval:org.opensuse.security:def:33875
    P
    Security update for python-cryptography (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:32531
    P
    ipsec-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33205
    P
    mipv6d on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28431
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29020
    P
    Security update for resource-agents (Important)
    2020-12-01
    oval:org.opensuse.security:def:29995
    P
    Security update for libtiff
    2020-12-01
    oval:org.opensuse.security:def:31078
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32666
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33228
    P
    perl-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34381
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28432
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29074
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:31115
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32760
    P
    opie on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33272
    P
    tcpdump on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28443
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:29123
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29634
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32817
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28511
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29162
    P
    Security update for libxml2 (Low)
    2020-12-01
    oval:org.opensuse.security:def:29635
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:28642
    P
    Security update for binutils
    2020-12-01
    oval:org.opensuse.security:def:29179
    P
    Security update for microcode_ctl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29646
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30338
    P
    Security update for transfig (Low)
    2020-12-01
    oval:org.opensuse.security:def:32441
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:35127
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28727
    P
    Security update for krb5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29223
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29719
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:30377
    P
    Security update for xalan-j2
    2020-12-01
    oval:org.opensuse.security:def:32442
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:34117
    P
    Recommended update for ncurses (Important)
    2020-12-01
    oval:org.opensuse.security:def:35167
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28784
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLED, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:29861
    P
    Security update for Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:29851
    P
    Security update for Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:30396
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:32453
    P
    Security update for xfsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33166
    P
    libnetpbm10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34274
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29897
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29938
    P
    Security update for libksba
    2020-12-01
    oval:org.opensuse.security:def:30440
    P
    Security update for yast2-storage (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:26458
    P
    USN-2310-1 -- krb5 vulnerabilities
    2014-10-13
    oval:org.mitre.oval:def:24122
    P
    ELSA-2013:0748: krb5 security update (Moderate)
    2014-05-26
    oval:org.mitre.oval:def:21099
    P
    RHSA-2013:0748: krb5 security update (Moderate)
    2014-02-17
    oval:com.ubuntu.precise:def:20131416000
    V
    CVE-2013-1416 on Ubuntu 12.04 LTS (precise) - medium.
    2013-04-19
    oval:com.ubuntu.trusty:def:20131416000
    V
    CVE-2013-1416 on Ubuntu 14.04 LTS (trusty) - medium.
    2013-04-19
    oval:com.redhat.rhsa:def:20130748
    P
    RHSA-2013:0748: krb5 security update (Moderate)
    2013-04-16
    BACK
    mit kerberos 5 *
    opensuse opensuse 11.4
    opensuse opensuse 12.1
    opensuse opensuse 12.2
    opensuse opensuse 12.3
    fedoraproject fedora 17
    fedoraproject fedora 18
    redhat enterprise linux desktop 6.0
    redhat enterprise linux eus 6.4
    redhat enterprise linux server 6.0
    redhat enterprise linux server aus 6.4
    redhat enterprise linux workstation 6.0