krb5: buffer overrun in kadmind with LDAP backend (MITKRB5-SA-2014-001)
Published Aug 14, 2014
8.5
HIGHCVSS 2.0
EPSS 8.09%
Description
Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) 1.6.x through 1.11.x before 1.11.6 and 1.12.x before 1.12.2 allows remote authenticated users to cause a denial of service (buffer overflow) or possibly execute arbitrary code via a series of "cpw -keepold" commands.
Affected products
No data.
- 1.6
- 1.6.1
- 1.6.2
- 1.7
- 1.7.1
- 1.8
- 1.8.1
- 1.8.2
- 1.8.3
- 1.8.4
- 1.8.5
- 1.8.6
- 1.9
- 1.9.1
- 1.9.2
- 1.9.3
- 1.9.4
- 1.10
- 1.10.1
- 1.10.2
- 1.10.3
- 1.10.4
- 1.11
- 1.11.1
- 1.11.2
- 1.11.3
- 1.11.4
- 1.11.5
- 1.12
- 1.12.1
No data.
Red Hat Enterprise Linux 5
krb5-0:1.6.1-80.el5_11
Fixed · RHSA-2014:1255
Red Hat Enterprise Linux 6
krb5-0:1.10.3-33.el6
Fixed · RHSA-2014:1389
Red Hat Enterprise Linux 7
krb5-0:1.12.2-14.el7
Fixed · RHSA-2015:0439
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | krb5-0:1.6.1-80.el5_11 | Fixed | RHSA-2014:1255 |
| Red Hat Enterprise Linux 6 | krb5-0:1.10.3-33.el6 | Fixed | RHSA-2014:1389 |
| Red Hat Enterprise Linux 7 | krb5-0:1.12.2-14.el7 | Fixed | RHSA-2015:0439 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:S/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.09% (0.08085) | 94.64th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.09% (0.08085) | 94.06th | v5 (v2026.06.15) |
| Mar 3, 2026 | 11.30% (0.11304) | 93.43th | v4 (v2025.03.14) |
| Dec 18, 2025 | 12.67% (0.12674) | 93.74th | v4 (v2025.03.14) |
| Nov 9, 2025 | 8.07% (0.08072) | 91.75th | v4 (v2025.03.14) |
| Mar 30, 2025 | 6.41% (0.06414) | 90.11th | v4 (v2025.03.14) |
| Mar 29, 2025 | 14.57% (0.14567) | 90.79th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.41% (0.06414) | 90.35th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.30% (0.01298) | 86.43th | v3 (v2023.03.01) |
| Feb 7, 2024 | 1.30% (0.01298) | 84.44th | v3 (v2023.03.01) |
| May 8, 2023 | 1.49% (0.01494) | 84.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.55% (0.01554) | 85.11th | v3 (v2023.03.01) |
| Mar 6, 2023 | 6.82% (0.06823) | 92.16th | v2 (v2022.01.01) |
| Apr 1, 2022 | 6.82% (0.06823) | 91.42th | v2 (v2022.01.01) |
| Feb 4, 2022 | 6.82% (0.06823) | 79.56th | v2 (v2022.01.01) |
References (34)
- http://advisories.mageia.org/MGASA-2014-0345.html x_refsource_CONFIRM
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 x_refsource_CONFIRM
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=7980 x_refsource_CONFIRM
- http://linux.oracle.com/errata/ELSA-2014-1255.html x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136640.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137056.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2014-08/msg00009.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00030.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2014-1255.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0439.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/59102 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59415 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59993 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60535 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60776 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61314 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61353 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201412-53.xml vendor-advisoryx_refsource_GENTOO
- http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2014-001.txt
- http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2014-001.txt x_refsource_CONFIRMVendor Advisory
- http://www.debian.org/security/2014/dsa-3000 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:165 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRM
- http://www.osvdb.org/109908 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/69168 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1030705 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2014-4345 Vendor Advisory
- https://blogs.oracle.com/sunsecurity/entry/cve_2014_4345_numeric_errors x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1128157 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95212 vdb-entryx_refsource_XF
- https://github.com/krb5/krb5/commit/dc7ed55c689d57de7f7408b34631bf06fec9dab1 x_refsource_CONFIRM
- https://github.com/krb5/krb5/pull/181 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-4345
- https://www.cve.org/CVERecord?id=CVE-2014-4345
Change history (0)
No recorded changes yet.