MIT krb5 1.22.2 及之前版本存在一个空指针解引用漏洞,该漏洞位于 KDC(密钥分发中心)的 函数中。在处理格式错误的名称时,该函数会返回成功,但会将客户端主体(client principal)保留为 NULL。恶意或已被攻陷的跨域可信 KDC 可以发送带有包含格式错误客户端名称的 PAC(特权属性证书)的 S4U2Proxy 请求,从而导致 krb5kdc 崩溃并拒绝身份验证服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet