Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2014-9421

Published: 3 February 2015

The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly handle partial XDR deserialization, which allows remote authenticated users to cause a denial of service (use-after-free and double free, and daemon crash) or possibly execute arbitrary code via malformed XDR data, as demonstrated by data sent to kadmind.

Priority

Medium

Status

Package Release Status
krb5
Launchpad, Ubuntu, Debian
lucid
Released (1.8.1+dfsg-2ubuntu0.14)
precise
Released (1.10+dfsg~beta1-2ubuntu0.6)
trusty
Released (1.12+dfsg-2ubuntu5.1)
upstream
Released (1.12.1+dfsg-17)
utopic
Released (1.12.1+dfsg-10ubuntu0.1)
Patches:
upstream: https://github.com/krb5/krb5/commit/a197e92349a4aa2141b5dff12e9dd44c2a2166e3
upstream: http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
Binaries built from this source package are in Universe and so are supported by the community.