CVE-2019-14844

HIGH EPSS 90.2%
Published Sep 26, 20196y ago · Modified Jun 17, 20262w ago
7.5 CVSS 3.1
High
Find Similar
Published Sep 26, 2019 6y ago
Last Modified Jun 17, 2026 2w ago

Description

A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.

CVSS Details

Base Score
7.5
Exploitability
3.9
Impact
3.6
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
90.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-628

Affected Products 4

VendorProductVersionRange
mitkerberos_5*≥1.16.1  –  ≤1.17.1
fedoraprojectfedora29any
fedoraprojectfedora30any
fedoraprojectfedora31any

References 6

  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14844
    Issue TrackingPatchThird Party Advisory
  • github.com https://github.com/krb5/krb5/pull/981
    PatchThird Party Advisory
  • lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/54ZYKEJZ77BXZWGF4NEVKC33ESVROEYC/
  • lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N4LS5PIJOCNOUZGLO2OBT6GY334PUOSW/
  • lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDE2QOKK4I4TV4WV74ZQWICZ4HJN2MOK/
  • security.netapp.com https://security.netapp.com/advisory/ntap-20220325-0003/
    Third Party Advisory

Remediation

  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14844
    Issue TrackingPatchThird Party Advisory
  • github.com https://github.com/krb5/krb5/pull/981
    PatchThird Party Advisory