PT-2014-1774 · Mit+6 · Mit Kerberos 5+6

Publicado

2014-07-20

·

Atualizado

2024-06-15

·

CVE-2014-4344

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (aka krb5) versions 1.5.x through 1.12.x before 1.12.2
Description The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via an empty continuation token during a SPNEGO negotiation. This can be exploited by an unauthenticated or partially authenticated remote attacker by sending an empty token as the second or later context token from initiator to acceptor. The exploitation of this issue may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For versions 1.5.x through 1.12.x before 1.12.2, update to version 1.12.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the SPNEGO negotiation functionality until a patch is available.

Correção

DoS

NULL Pointer Dereference

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2418
BDU:2015-01984
CESA-2014_1389
CESA-2015_0439
CVE-2014-4344
DLA-37-1
DSA-3000-1
MGASA-2014-0345
OPENSUSE-SU-2024:10004-1
RHSA-2014:1245
RHSA-2014:1389
RHSA-2014_1245
RHSA-2014_1389
RHSA-2015:0439
RHSA-2015_0439
USN-2310-1

Produtos afetados

Alt Linux
Centos
Ibm Aix
Mit Kerberos 5
Red Hat
Suse
Ubuntu