PT-2014-1773 · Mit+5 · Mit Kerberos 5+5

Publicado

2014-07-20

·

Atualizado

2024-06-15

·

CVE-2014-4342

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (aka krb5) versions 1.7.x through 1.12.x before 1.12.2
Description The issue allows remote attackers to cause a denial of service by injecting invalid tokens into a GSSAPI application session, potentially leading to a buffer over-read or NULL pointer dereference and application crash. This can be exploited by a remote attacker who has passed the authentication procedure, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations For versions 1.7.x through 1.12.x before 1.12.2, update to version 1.12.2 or later to resolve the issue. As a temporary workaround, consider restricting access to GSSAPI application sessions to minimize the risk of exploitation.

Correção

DoS

Buffer Overflow

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2418
BDU:2015-01984
CESA-2014_1389
CESA-2015_0439
CVE-2014-4342
DLA-37-1
DSA-3000-1
MGASA-2014-0345
OPENSUSE-SU-2024:10004-1
RHSA-2014:1389
RHSA-2014_1389
RHSA-2015:0439
RHSA-2015_0439
USN-2310-1

Produtos afetados

Alt Linux
Centos
Mit Kerberos 5
Red Hat
Suse
Ubuntu