PT-2014-6431 · Mit+3 · Mit Kerberos 5+3

Published

2014-12-05

·

Updated

2024-06-15

·

CVE-2014-5354

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (aka krb5) versions 1.12.x through 1.13.0
Description The issue allows remote authenticated users to cause a denial of service, resulting in a daemon crash due to a NULL pointer dereference. This can be achieved by creating a database entry for a keyless principal. The estimated number of potentially affected devices worldwide is not specified. Real-world incidents where this issue was exploited are not mentioned.
Recommendations For MIT Kerberos 5 (aka krb5) versions 1.12.x through 1.13.0, update to version 1.13.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the add principal and purgekeys commands in kadmin to minimize the risk of exploitation. Avoid creating database entries for keyless principals until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2014-2418
ALT-PU-2014-2482
CVE-2014-5354
OPENSUSE-SU-2024:10004-1
SUSE-SU-2015:1276-1
SUSE-SU-2015:1282-1
USN-2498-1

Affected Products

Alt Linux
Mit Kerberos 5
Suse
Ubuntu