Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

CVE-2013-1416 MIT Kerberos Denial of Service: Is a patch/update available?

I perform vulnerability management for numerous MAC systems which are currently scanning hot (using eEye's Retina software) for the CVE I referenced in the thread subject. MIT seems to receommend only using the version of Kerberos which shipped with the MACs, but the resolution to this issue is to update the Kerberos version to 1.10.5. Currently, the machines are using Kerberos 5 Release 1.7. Is there a valid patch or update available? Thanks!

MacBook Pro, Mac OS X (10.6.8)

Posted on Jun 26, 2013 9:02 AM

Reply
1 reply

Jun 26, 2013 3:13 PM in response to t3chGuy81

If you want or need an official answer, please contact Apple directly.


There are no references to that CVE published at the Apple web site (other than this one), nor do I see any OS X references within the CVE itself.


If you're patched to current, then there are no announced patches available for your software.


If security and stability is a concern, then OS X 10.6.8 is rather old and generally no longer receiving patches and updates, so an OS X upgrade for your particular Mac systems may be appropriate.


I don't know if this has been patched in the most current OS X software, and don't have a 10.8 system handy to check.


As for the error, vulnerability scanners are renowned for false positives and for spurious diagnostics; some knowledge of the issue that's being detected is generally required, and a decision whether that's relevant to your environment often follows.


According to the CVE database, this is remote-accessible bug that can cause the Kerberos daemon to crash, but you need to authenticate to trigger it. It doesn't provide further access; it's a DoS. (Given there are other ways to trigger network-nased DoSs in most any configuration I'm dealing with, this CVE would seem to rank as yet another annoyance in the pantheon of network annoyances, but not AFAICT as a crisis.)


I'd be tempted to drop a Proper Use of Resources notice on somebody that tried that on one of the servers I administer, but that's fodder for another discussion.

CVE-2013-1416 MIT Kerberos Denial of Service: Is a patch/update available?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.