PT-2014-1773 · Mit+5 · Mit Kerberos 5+5

Published

2014-07-20

·

Updated

2024-06-15

·

CVE-2014-4342

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (aka krb5) versions 1.7.x through 1.12.x before 1.12.2
Description The issue allows remote attackers to cause a denial of service by injecting invalid tokens into a GSSAPI application session, potentially leading to a buffer over-read or NULL pointer dereference and application crash. This can be exploited by a remote attacker who has passed the authentication procedure, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations For versions 1.7.x through 1.12.x before 1.12.2, update to version 1.12.2 or later to resolve the issue. As a temporary workaround, consider restricting access to GSSAPI application sessions to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2418
BDU:2015-01984
CESA-2014_1389
CESA-2015_0439
CVE-2014-4342
DLA-37-1
DSA-3000-1
MGASA-2014-0345
OPENSUSE-SU-2024:10004-1
RHSA-2014:1389
RHSA-2014_1389
RHSA-2015:0439
RHSA-2015_0439
USN-2310-1

Affected Products

Alt Linux
Centos
Mit Kerberos 5
Red Hat
Suse
Ubuntu