UBUNTU-CVE-2017-7482
In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
02 / AFFECTED SOFTWARE
Affected packages
117 explicit affected versions
34 explicit affected versions
56 explicit affected versions
14 explicit affected versions
12 explicit affected versions
17 explicit affected versions
32 explicit affected versions
29 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
05 / REFERENCES
Further evidence
- http://seclists.org/oss-sec/2017/q2/602
- https://git.kernel.org/torvalds/c/5f2f97656ada8d811d3c1bef503ced266fcd53a0
- https://ubuntu.com/security/CVE-2017-7482
- https://ubuntu.com/security/notices/USN-3377-1
- https://ubuntu.com/security/notices/USN-3377-2
- https://ubuntu.com/security/notices/USN-3378-1
- https://ubuntu.com/security/notices/USN-3378-2
- https://ubuntu.com/security/notices/USN-3381-1
- https://ubuntu.com/security/notices/USN-3381-2
- https://www.cve.org/CVERecord?id=CVE-2017-7482