PT-2014-6431 · Mit+3 · Mit Kerberos 5+3
Published
2014-12-05
·
Updated
2024-06-15
·
CVE-2014-5354
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
MIT Kerberos 5 (aka krb5) versions 1.12.x through 1.13.0
Description
The issue allows remote authenticated users to cause a denial of service, resulting in a daemon crash due to a NULL pointer dereference. This can be achieved by creating a database entry for a keyless principal. The estimated number of potentially affected devices worldwide is not specified. Real-world incidents where this issue was exploited are not mentioned.
Recommendations
For MIT Kerberos 5 (aka krb5) versions 1.12.x through 1.13.0, update to version 1.13.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
add principal and purgekeys commands in kadmin to minimize the risk of exploitation. Avoid creating database entries for keyless principals until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Mit Kerberos 5
Suse
Ubuntu