CVE-2017-15088 -- krb5ID: oval:org.secpod.oval:def:2000005 | Date: (C)2019-06-03 (M)2023-12-20 |
Class: VULNERABILITY | Family: unix |
plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 through 1.15.2 mishandles Distinguished Name fields, which allows remote attackers to execute arbitrary code or cause a denial of service in situations involving untrusted X.509 data, related to the get_matching_data and X509_NAME_oneline_ex functions. NOTE: this has security relevance only in use cases outside of the MIT Kerberos distribution, e.g., the use of get_matching_data in KDC certauth plugin code that is specific to Red Hat.
Platform: |
Debian 8.x |
Debian 9.x |