[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3153-1 krb5 -- krb5

ID: oval:org.secpod.oval:def:601948Date: (C)2015-02-10   (M)2023-12-07
Class: PATCHFamily: unix




Multiples vulnerabilities have been found in krb5, the MIT implementation of Kerberos: CVE-2014-5352 Incorrect memory management in the libgssapi_krb5 library might result in denial of service or the execution of arbitrary code. CVE-2014-9421 Incorrect memory management in kadmind"s processing of XDR data might result in denial of service or the execution of arbitrary code. CVE-2014-9422 Incorrect processing of two-component server principals might result in impersonation attacks. CVE-2014-9423 An information leak in the libgssrpc library.

Platform:
Debian 7.0
Product:
krb5-kdc
krb5-kdc-ldap
krb5-admin-server
Reference:
DSA-3153-1
CVE-2014-5352
CVE-2014-9421
CVE-2014-9422
CVE-2014-9423
CVE    4
CVE-2014-5352
CVE-2014-9423
CVE-2014-9422
CVE-2014-9421
...
CPE    4
cpe:/a:mit:krb5-admin-server
cpe:/o:debian:debian_linux:7.x
cpe:/a:mit:krb5-kdc-ldap
cpe:/a:mit:krb5-kdc
...

© SecPod Technologies