Red Hat Bugzilla – Bug 1473560
CVE-2017-11368 krb5: Invalid S4U2Self or S4U2Proxy request causes assertion failure
Last modified: 2018-10-19 17:42:27 EDT
It was found that in MIT krb5 1.7 and later, an authenticated attacker can cause an assertion failure in krb5kdc by sending an invalid S4U2Self or S4U2Proxy request. Upstream patch: https://github.com/krb5/krb5/pull/678/commits/ffb35baac698
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:0666 https://access.redhat.com/errata/RHSA-2018:0666