PT-2015-3795 · Mit+6 · Mit Kerberos 5+6
Publicado
2015-01-21
·
Atualizado
2024-06-15
·
CVE-2014-5352
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MIT Kerberos 5 versions 1.11.5 and earlier, 1.12.x through 1.12.2, 1.13.x before 1.13.1
Description
The issue is related to the improper maintenance of security-context handles in the krb5 gss process context token function. This allows remote authenticated users to cause a denial of service, including use-after-free and double free errors, and daemon crash, or possibly execute arbitrary code via crafted GSSAPI traffic.
Recommendations
For versions 1.11.5 and earlier, update to a version later than 1.11.5.
For versions 1.12.x through 1.12.2, update to a version later than 1.12.2.
For versions 1.13.x before 1.13.1, update to version 1.13.1 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Ibm Aix
Mit Kerberos 5
Red Hat
Suse
Ubuntu