A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DES, triple-DES, or RC4), the attacker can crash the KDC by making an S4U2Self request.
References
Configurations
History
No history.
Information
Published : 2018-12-26 21:29
Updated : 2024-11-21 04:01
NVD link : CVE-2018-20217
Mitre link : CVE-2018-20217
CVE.ORG link : CVE-2018-20217
JSON object : View
Products Affected
mit
- kerberos
debian
- debian_linux
CWE
CWE-617
Reachable Assertion