MGASA-2014-0345
Dashboard / Vulnerabilities / MGASA-2014-0345
MGASA-2014-0345
Summary: Updated krb5 package fixes security vulnerabilities
Details: MIT Kerberos 5 allows attackers to cause a denial of service via a buffer over-read or NULL pointer dereference, by injecting invalid tokens into a GSSAPI application session (CVE-2014-4341, CVE-2014-4342). MIT Kerberos 5 allows attackers to cause a denial of service via a double-free flaw or NULL pointer dereference, while processing invalid SPNEGO tokens (CVE-2014-4343, CVE-2014-4344). In MIT Kerberos 5, when kadmind is configured to use LDAP for the KDC database, an authenticated remote attacker can cause it to perform an out-of-bounds write (buffer overflow) (CVE-2014-4345).
References: https://advisories.mageia.org/MGASA-2014-0345.html, https://bugs.mageia.org/show_bug.cgi?id=13882, http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2014-001.txt, https://lists.fedoraproject.org/pipermail/package-announce/2014-August/136360.html
Affected packages
Package
Name: krb5
Purl: pkg:rpm/mageia/krb5?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
