CVE-2015-2698

high
Published 2015-11-13 · Modified 2026-05-06
CVSS v3
CVSS v2
8.5
VIR risk
8.5

Description

The iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly accesses a certain pointer, which allows remote authenticated users to cause a denial of service (memory corruption) or possibly have unspecified other impact by interacting with an application that calls the gss_export_sec_context function. NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-2696.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-2698

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://krbdev.mit.edu/rt/Ticket/Display.html?id=8273

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.13.2+dfsg-4
debian debianbullseyefixed1.13.2+dfsg-4
debian debianforkyfixed1.13.2+dfsg-4
debian debiansidfixed1.13.2+dfsg-4
debian debiantrixiefixed1.13.2+dfsg-4

Application impact

VendorProductVersionsFixed
mitkerberos_51.14

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.