CVE-2015-2695 PUBLISHED

lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.

EPSS 5.39% · 90.1th percentile

Risk Scores

EPSS Score
5.39%
90.1th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSkrb50, 1.10.1+dfsg-6.1ubuntu1, 1.11.3+dfsg-3ubuntu2

Timeline

References

Open in Interactive Console →