USN-6467-2
Dashboard / Vulnerabilities / USN-6467-2
USN-6467-2
Summary: krb5 vulnerability
Details: USN-6467-1 fixed a vulnerability in Kerberos. This update provides the corresponding update for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 23.04. Original advisory details: Robert Morris discovered that Kerberos did not properly handle memory access when processing RPC data through kadmind, which could lead to the freeing of uninitialized memory. An authenticated remote attacker could possibly use this issue to cause kadmind to crash, resulting in a denial of service.
References: https://ubuntu.com/security/notices/USN-6467-2, https://ubuntu.com/security/CVE-2023-36054
Affected packages
Package
Name: krb5
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
