krb5: double-free flaw in SPNEGO initiators
Published Aug 14, 2014
7.6
HIGHCVSS 2.0
EPSS 6.42%
Description
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies a security mechanism different from the one proposed by the initiator.
Affected products
No data.
Configuration 1
- 7.0
Configuration 2
- 1.10
- 1.10.1
- 1.10.2
- 1.10.3
- 1.10.4
- 1.11
- 1.11.1
- 1.11.2
- 1.11.3
- 1.11.4
- 1.11.5
- 1.12
- 1.12.1
Configuration 3
- 7.0
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 6
krb5-0:1.10.3-33.el6
Fixed · RHSA-2014:1389
Red Hat Enterprise Linux 7
krb5-0:1.12.2-14.el7
Fixed · RHSA-2015:0439
Red Hat Enterprise Linux 5
krb5
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | krb5-0:1.10.3-33.el6 | Fixed | RHSA-2014:1389 |
| Red Hat Enterprise Linux 7 | krb5-0:1.12.2-14.el7 | Fixed | RHSA-2015:0439 |
| Red Hat Enterprise Linux 5 | krb5 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the version of krb5 as shipped with Red Hat Enterprise Linux 5.
References (22)
- http://advisories.mageia.org/MGASA-2014-0345.html x_refsource_CONFIRM
- http://aix.software.ibm.com/aix/efixes/security/nas_advisory1.asc x_refsource_CONFIRM
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=7969 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136360.html vendor-advisoryx_refsource_FEDORA
- http://rhn.redhat.com/errata/RHSA-2015-0439.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/59102 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60082 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60448 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61052 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201412-53.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15553.html x_refsource_CONFIRM
- http://www.debian.org/security/2014/dsa-3000 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.osvdb.org/109390 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/69159 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1030706 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2014-4343 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1121876 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-4270 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95211 vdb-entryx_refsource_XF
- https://github.com/krb5/krb5/commit/f18ddf5d82de0ab7591a36e465bc24225776940f x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-4343
- https://www.cve.org/CVERecord?id=CVE-2014-4343
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data