A memory leak flaw was found in the krb5_unparse_name() function of the MIT Kerberos kadmind service. An authenticated attacker could repeatedly send specially crafted requests to the server, which could cause the server to consume large amounts of memory resources, ultimately leading to a denial of service due to memory exhaustion.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | krb5 | 2016-04-21 16:00 | ALAS-2016-691 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 4.0 | AV:N/AC:L/Au:S/C:N/I:N/A:P |
NVD | CVSSv2 | 4.0 | AV:N/AC:L/Au:S/C:N/I:N/A:P |
NVD | CVSSv3 | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |