CVE-2014-9421
Published: 3 February 2015
The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly handle partial XDR deserialization, which allows remote authenticated users to cause a denial of service (use-after-free and double free, and daemon crash) or possibly execute arbitrary code via malformed XDR data, as demonstrated by data sent to kadmind.
Priority
Status
Package | Release | Status |
---|---|---|
krb5 Launchpad, Ubuntu, Debian |
lucid |
Released
(1.8.1+dfsg-2ubuntu0.14)
|
precise |
Released
(1.10+dfsg~beta1-2ubuntu0.6)
|
|
trusty |
Released
(1.12+dfsg-2ubuntu5.1)
|
|
upstream |
Released
(1.12.1+dfsg-17)
|
|
utopic |
Released
(1.12.1+dfsg-10ubuntu0.1)
|
|
Patches: upstream: https://github.com/krb5/krb5/commit/a197e92349a4aa2141b5dff12e9dd44c2a2166e3 upstream: http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt |
||
Binaries built from this source package are in Universe and so are supported by the community. |