vulnerability

CentOS Linux: CVE-2020-17049: Moderate: krb5 security, bug fix, and enhancement update (Multiple Advisories)

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Nov 11, 2020
Added
May 15, 2023
Modified
Jan 11, 2024

Description

<p>A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD).</p>
<p>To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the KDC to accept it.</p>
<p>The update addresses this vulnerability by changing how the KDC validates service tickets used with KCD.</p>

Solutions

centos-upgrade-bind-dyndb-ldapcentos-upgrade-bind-dyndb-ldap-debuginfocentos-upgrade-bind-dyndb-ldap-debugsourcecentos-upgrade-custodiacentos-upgrade-ipa-clientcentos-upgrade-ipa-client-commoncentos-upgrade-ipa-client-debuginfocentos-upgrade-ipa-client-epncentos-upgrade-ipa-client-sambacentos-upgrade-ipa-commoncentos-upgrade-ipa-debuginfocentos-upgrade-ipa-debugsourcecentos-upgrade-ipa-healthcheckcentos-upgrade-ipa-healthcheck-corecentos-upgrade-ipa-python-compatcentos-upgrade-ipa-selinuxcentos-upgrade-ipa-servercentos-upgrade-ipa-server-commoncentos-upgrade-ipa-server-debuginfocentos-upgrade-ipa-server-dnscentos-upgrade-ipa-server-trust-adcentos-upgrade-ipa-server-trust-ad-debuginfocentos-upgrade-krb5-debuginfocentos-upgrade-krb5-debugsourcecentos-upgrade-krb5-develcentos-upgrade-krb5-libscentos-upgrade-krb5-libs-debuginfocentos-upgrade-krb5-pkinitcentos-upgrade-krb5-pkinit-debuginfocentos-upgrade-krb5-servercentos-upgrade-krb5-server-debuginfocentos-upgrade-krb5-server-ldapcentos-upgrade-krb5-server-ldap-debuginfocentos-upgrade-krb5-workstationcentos-upgrade-krb5-workstation-debuginfocentos-upgrade-libkadm5centos-upgrade-libkadm5-debuginfocentos-upgrade-opendnsseccentos-upgrade-opendnssec-debuginfocentos-upgrade-opendnssec-debugsourcecentos-upgrade-python3-custodiacentos-upgrade-python3-ipaclientcentos-upgrade-python3-ipalibcentos-upgrade-python3-ipaservercentos-upgrade-python3-ipatestscentos-upgrade-python3-jwcryptocentos-upgrade-python3-kdcproxycentos-upgrade-python3-pyusbcentos-upgrade-python3-qrcodecentos-upgrade-python3-qrcode-corecentos-upgrade-python3-yubicocentos-upgrade-slapi-niscentos-upgrade-slapi-nis-debuginfocentos-upgrade-slapi-nis-debugsourcecentos-upgrade-softhsmcentos-upgrade-softhsm-debuginfocentos-upgrade-softhsm-debugsourcecentos-upgrade-softhsm-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.