Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Update for krb5 RHSA-2014:1389-02
Summary:The remote host is missing an update for the 'krb5'; package(s) announced via the referenced advisory.
The remote host is missing an update for the 'krb5'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Kerberos is a networked authentication system which allows clients and
servers to authenticate to each other with the help of a trusted third
party, the Kerberos KDC.

It was found that if a KDC served multiple realms, certain requests could
cause the setup_server_realm() function to dereference a NULL pointer.
A remote, unauthenticated attacker could use this flaw to crash the KDC
using a specially crafted request. (CVE-2013-1418, CVE-2013-6800)

A NULL pointer dereference flaw was found in the MIT Kerberos SPNEGO
acceptor for continuation tokens. A remote, unauthenticated attacker could
use this flaw to crash a GSSAPI-enabled server application. (CVE-2014-4344)

A buffer overflow was found in the KADM5 administration server (kadmind)
when it was used with an LDAP back end for the KDC database. A remote,
authenticated attacker could potentially use this flaw to execute arbitrary
code on the system running kadmind. (CVE-2014-4345)

Two buffer over-read flaws were found in the way MIT Kerberos handled
certain requests. A remote, unauthenticated attacker who is able to inject
packets into a client or server application's GSSAPI session could use
either of these flaws to crash the application. (CVE-2014-4341,

A double-free flaw was found in the MIT Kerberos SPNEGO initiators.
An attacker able to spoof packets to appear as though they are from an
GSSAPI acceptor could use this flaw to crash a client application that uses
MIT Kerberos. (CVE-2014-4343)

These updated krb5 packages also include several bug fixes. Space precludes
documenting all of these changes in this advisory. Users are directed to
the Red Hat Enterprise Linux 6.6 Technical Notes, linked to in the
References section, for information on the most significant of these

All krb5 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.

Affected Software/OS:
krb5 on Red Hat Enterprise Linux Desktop (v. 6),
Red Hat Enterprise Linux Server (v. 6),
Red Hat Enterprise Linux Workstation (v. 6)

Please Install the Updated Packages.

CVSS Score:

CVSS Vector:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-1418
BugTraq ID: 63555
SuSE Security Announcement: openSUSE-SU-2013:1738 (Google Search)
SuSE Security Announcement: openSUSE-SU-2013:1751 (Google Search)
SuSE Security Announcement: openSUSE-SU-2013:1833 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2013-6800
BugTraq ID: 63770
Common Vulnerability Exposure (CVE) ID: CVE-2014-4341
BugTraq ID: 68909
Debian Security Information: DSA-3000 (Google Search)
RedHat Security Advisories: RHSA-2015:0439
XForce ISS Database: mit-kerberos-cve20144341-dos(94904)
Common Vulnerability Exposure (CVE) ID: CVE-2014-4342
BugTraq ID: 68908
XForce ISS Database: mit-kerberos-cve20144342-dos(94903)
Common Vulnerability Exposure (CVE) ID: CVE-2014-4343
BugTraq ID: 69159
XForce ISS Database: kerberos-cve20144343-dos(95211)
Common Vulnerability Exposure (CVE) ID: CVE-2014-4344
BugTraq ID: 69160
XForce ISS Database: kerberos-cve20144344-dos(95210)
Common Vulnerability Exposure (CVE) ID: CVE-2014-4345
BugTraq ID: 69168
RedHat Security Advisories: RHSA-2014:1255
SuSE Security Announcement: SUSE-SU-2014:1028 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:1043 (Google Search)
XForce ISS Database: kerberos-cve20144345-bo(95212)
CopyrightCopyright (C) 2014 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.