{"id":"USN-2810-1","summary":"krb5 vulnerabilities","details":"It was discovered that the Kerberos kpasswd service incorrectly handled\ncertain UDP packets. A remote attacker could possibly use this issue to\ncause resource consumption, resulting in a denial of service. This issue\nonly affected Ubuntu 12.04 LTS. (CVE-2002-2443)\n\nIt was discovered that Kerberos incorrectly handled null bytes in certain\ndata fields. A remote attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-5355)\n\nIt was discovered that the Kerberos kdcpreauth modules incorrectly tracked\ncertain client requests. A remote attacker could possibly use this issue\nto bypass intended preauthentication requirements. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-2694)\n\nIt was discovered that Kerberos incorrectly handled certain SPNEGO packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2695)\n\nIt was discovered that Kerberos incorrectly handled certain IAKERB packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2696, CVE-2015-2698)\n\nIt was discovered that Kerberos incorrectly handled certain TGS requests. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2015-2697)\n","modified":"2026-04-22T09:18:36.934079Z","published":"2015-11-12T17:50:55Z","related":["UBUNTU-CVE-2014-5355","UBUNTU-CVE-2015-2694","UBUNTU-CVE-2015-2695","UBUNTU-CVE-2015-2696","UBUNTU-CVE-2015-2697","UBUNTU-CVE-2015-2698"],"upstream":["CVE-2002-2443","CVE-2014-5355","CVE-2015-2694","CVE-2015-2695","CVE-2015-2696","CVE-2015-2697","CVE-2015-2698","UBUNTU-CVE-2002-2443","UBUNTU-CVE-2014-5355","UBUNTU-CVE-2015-2694","UBUNTU-CVE-2015-2695","UBUNTU-CVE-2015-2696","UBUNTU-CVE-2015-2697","UBUNTU-CVE-2015-2698"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-2810-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2002-2443"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-5355"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-2694"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-2695"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-2696"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-2697"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-2698"}],"affected":[{"package":{"name":"krb5","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/krb5@1.12+dfsg-2ubuntu5.2?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12+dfsg-2ubuntu5.2"}]}],"versions":["1.10.1+dfsg-6.1ubuntu1","1.11.3+dfsg-3ubuntu2","1.12+dfsg-2ubuntu1","1.12+dfsg-2ubuntu2","1.12+dfsg-2ubuntu3","1.12+dfsg-2ubuntu4","1.12+dfsg-2ubuntu4.2","1.12+dfsg-2ubuntu5","1.12+dfsg-2ubuntu5.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"krb5-admin-server","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"krb5-gss-samples","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"krb5-kdc","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"krb5-kdc-ldap","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"krb5-locales","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"krb5-multidev","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"krb5-otp","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"krb5-pkinit","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"krb5-user","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"libgssapi-krb5-2","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"libgssrpc4","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"libk5crypto3","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"libkadm5clnt-mit9","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"libkadm5srv-mit8","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"libkadm5srv-mit9","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"libkdb5-7","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"libkrad0","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"libkrb5-3","binary_version":"1.12+dfsg-2ubuntu5.2"},{"binary_name":"libkrb5support0","binary_version":"1.12+dfsg-2ubuntu5.2"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2014-5355","severity":[{"score":"low","type":"Ubuntu"}]},{"id":"CVE-2015-2694","severity":[{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2015-2695","severity":[{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2015-2696","severity":[{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2015-2697","severity":[{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2015-2698","severity":[{"score":"medium","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:14.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2810-1.json"}}],"schema_version":"1.7.5"}