Vulnerability Name: | CVE-2013-6800 (CCN-89060) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2013-11-04 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2013-11-04 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2020-01-21 | ||||||||||||||||||||||||||||||||||||||||
Summary: | An unspecified third-party database module for the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.10.x allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request, a different vulnerability than CVE-2013-1418. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.2 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other CWE-476 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-6800 Source: CCN Type: Kerberos Ticket #7757 Multi-realm KDC null deref [CVE-2013-1418] Source: CONFIRM Type: UNKNOWN http://krbdev.mit.edu/rt/Ticket/Display.html?id=7757 Source: CCN Type: RHSA-2014-1245 Moderate: krb5 security and bug fix update Source: CCN Type: RHSA-2014-1389 Moderate: krb5 security and bug fix update Source: CCN Type: IBM Security Bulletin 1690820 IBM Security Network Protection is affected by krb5 vulnerability (CVE-2014-1568) Source: BID Type: UNKNOWN 63770 Source: CCN Type: BID-63770 MIT Kerberos 5 CVE-2013-6800 Remote Denial of Service Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 1031499 (CVE-2013-6800) CVE-2013-6800 krb5: KDC remote DoS (NULL pointer dereference and daemon crash) Source: XF Type: UNKNOWN mit-kerberos-cve20136800-dos(89060) Source: CCN Type: Kerberos GIT Repository Multi-realm KDC null deref [CVE-2013-1418] Source: CONFIRM Type: Patch https://github.com/krb5/krb5/commit/c2ccf4197f697c4ff143b8a786acdd875e70a89d Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-6800 | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration RedHat 9: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |