UBUNTU-CVE-2014-9423
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-9423
UBUNTU-CVE-2014-9423
Summary:
Details: The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.
References: https://ubuntu.com/security/CVE-2014-9423, http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt, https://ubuntu.com/security/notices/USN-2498-1, https://www.cve.org/CVERecord?id=CVE-2014-9423
Affected packages
Package
Name: krb5
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu5.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
