CVE-2018-20217
MEDIUMMIT Kerberos < 1.17 - Denial of Service via S4U2Self Request with Older Encryption Type
Title source: llmDescription
A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DES, triple-DES, or RC4), the attacker can crash the KDC by making an S4U2Self request.
References (6)
Core 6
Core References
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2KNHELH4YHNT6H2ESJWX2UIDXLBNGB2O/
Patch, Third Party Advisory x_refsource_confirm
http://krbdev.mit.edu/rt/Ticket/Display.html?id=8763
Patch, Third Party Advisory x_refsource_confirm
https://github.com/krb5/krb5/commit/5e6d1796106df8ba6bc1973ee0917c170d929086
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/01/msg00020.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190416-0006/
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/09/msg00019.html
Scores
CVSS v3
5.3
EPSS
0.0238
EPSS Percentile
85.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-617
Status
published
Products (3)
debian/debian_linux
8.0
debian/debian_linux
9.0
mit/kerberos
< 5-1.17
Published
Dec 26, 2018
Tracked Since
Feb 18, 2026