It was reported [1] that if a KDC serves multiple realms, certain requests could cause the setup_server_realm() funtion to dereference a null pointer, resulting in a crash of the KDC (Key Distribution Center). This can be triggered by an unauthenticated user. This has been correct in git [2]. [1] http://mailman.mit.edu/pipermail/krb5-bugs/2013-November/010206.html [2] https://github.com/krb5/krb5/commit/5d2d9a1abe46a2c1a8614d4672d08d9d30a5f8bf
Upstream ticket: http://krbdev.mit.edu/rt/Ticket/Display.html?id=7757
Created krb5 tracking bugs for this issue: Affects: fedora-all [bug 1026997]
krb5-1.11.3-29.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
krb5-1.11.3-13.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
Note: This issue can be triggered only if multiple realms are served from one KDC Statement: (none)
IssueDescription: It was found that if a KDC served multiple realms, certain requests could cause the setup_server_realm() function to dereference a NULL pointer. A remote, unauthenticated attacker could use this flaw to crash the KDC using a specially crafted request.
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Via RHSA-2014:1245 https://rhn.redhat.com/errata/RHSA-2014-1245.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2014:1389 https://rhn.redhat.com/errata/RHSA-2014-1389.html