GHSA-mffc-9gx5-99g3
Dashboard / Vulnerabilities / GHSA-mffc-9gx5-99g3
GHSA-mffc-9gx5-99g3
Summary: python-kerberos vulnerable to KDC spoofing attacks
Details: The `checkPassword` function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-3206, https://github.com/apple/ccs-pykerberos/issues/31, https://github.com/apple/ccs-pykerberos/commit/9cb61c93f9b24dd18a0a315f3df5445529c5c333, https://bugzilla.redhat.com/show_bug.cgi?id=1223802, https://github.com/apple/ccs-pykerberos, https://github.com/pypa/advisory-database/tree/main/vulns/kerberos/PYSEC-2017-49.yaml, https://github.com/pypa/advisory-database/tree/main/vulns/pykerberos/PYSEC-2017-66.yaml, https://pypi.python.org/pypi/kerberos, https://web.archive.org/web/20150910143429/https://trac.calendarserver.org/ticket/833, https://web.archive.org/web/20200228090829/http://www.securityfocus.com/bid/74760, http://www.openwall.com/lists/oss-security/2015/05/21/3
Affected packages
Package
Name: kerberos
Purl: pkg:pypi/kerberos
Affected ranges
Type: ECOSYSTEM
Events:
