CVE-2014-4342
published 2014-07-20CVE-2014-4342: MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.52%
93.0th percentile
MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | krb5 | < krb5 1.12.1+dfsg-4 (bookworm) | krb5 1.12.1+dfsg-4 (bookworm) |
| mit | kerberos | — | — |
| mit | kerberos | — | — |
| mit | kerberos | — | — |
| mit | kerberos | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-734c-f6jq-56f9: MIT Kerberos 5 (aka krb5) 1
ghsa_unreviewed·2022-05-13
CVE-2014-4342 [MEDIUM] CWE-119 GHSA-734c-f6jq-56f9: MIT Kerberos 5 (aka krb5) 1
MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.
OSV
krb5 vulnerabilities
osv·2014-08-11·CVSS 5.0
CVE-2012-1016 [MEDIUM] krb5 vulnerabilities
krb5 vulnerabilities
It was discovered that Kerberos incorrectly handled certain crafted Draft 9
requests. A remote attacker could use this issue to cause the daemon to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-1016)
It was discovered that Kerberos incorrectly handled certain malformed
KRB5_PADATA_PK_AS_REQ AS-REQ requests. A remote attacker could use this
issue to cause the daemon to crash, resulting in a denial of service. This
issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS. (CVE-2013-1415)
It was discovered that Kerberos incorrectly handled certain crafted TGS-REQ
requests. A remote authenticated attacker could use this issue to cause the
daemon to crash, resulting in a denial of service. This issue only affected
Ubuntu 1
OSV
CVE-2014-4342: MIT Kerberos 5 (aka krb5) 1
osv·2014-07-20·CVSS 5.0
CVE-2014-4342 [MEDIUM] CVE-2014-4342: MIT Kerberos 5 (aka krb5) 1
MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.
Ubuntu
Kerberos vulnerabilities
vendor_ubuntu·2014-08-11·CVSS 5.0
CVE-2012-1016 [MEDIUM] Kerberos vulnerabilities
Title: Kerberos vulnerabilities
Summary: Several security issues were fixed in Kerberos.
It was discovered that Kerberos incorrectly handled certain crafted Draft 9
requests. A remote attacker could use this issue to cause the daemon to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-1016)
It was discovered that Kerberos incorrectly handled certain malformed
KRB5_PADATA_PK_AS_REQ AS-REQ requests. A remote attacker could use this
issue to cause the daemon to crash, resulting in a denial of service. This
issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS. (CVE-2013-1415)
It was discovered that Kerberos incorrectly handled certain crafted TGS-REQ
requests. A remote authenticated attacker could use this issue to cause the
daemon to crash
Red Hat
krb5: denial of service flaws when handling RFC 1964 tokens
vendor_redhat·2014-06-26·CVSS 5.0
CVE-2014-4342 [MEDIUM] CWE-125 krb5: denial of service flaws when handling RFC 1964 tokens
krb5: denial of service flaws when handling RFC 1964 tokens
MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.
A buffer over-read flaw was found in the way MIT Kerberos handled certain requests. A remote, unauthenticated attacker who is able to inject packets into a client or server application's GSSAPI session could use this flaw to crash the application.
Statement: This issue did not affect the version of krb5 as shipped with Red Hat Enterprise Linux 5.
Package: krb5 (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-4342: krb5 - MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attac...
vendor_debian·2014·CVSS 5.0
CVE-2014-4342 [MEDIUM] CVE-2014-4342: krb5 - MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attac...
MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.
Scope: local
bookworm: resolved (fixed in 1.12.1+dfsg-4)
bullseye: resolved (fixed in 1.12.1+dfsg-4)
forky: resolved (fixed in 1.12.1+dfsg-4)
sid: resolved (fixed in 1.12.1+dfsg-4)
trixie: resolved (fixed in 1.12.1+dfsg-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4342 krb5: denial of service flaws when handling RFC 1964 tokens
bugzilla·2014-07-17·CVSS 5.0
CVE-2014-4342 [MEDIUM] CVE-2014-4342 krb5: denial of service flaws when handling RFC 1964 tokens
CVE-2014-4342 krb5: denial of service flaws when handling RFC 1964 tokens
In MIT krb5 releases krb5-1.7 and later, an unauthenticated remote attacker with the ability to inject packets into a legitimately established GSSAPI application session can cause a program crash due to invalid memory references when reading beyond the end of a buffer or by causing a null pointer dereference.
References:
http://diswww.mit.edu:8008/menelaus.mit.edu/cvs-krb5/28388
https://github.com/krb5/krb5/commit/fb99962cbd063ac04c9a9d2cc7c75eab73f3533d
Discussion:
A remote unauthenticated attacker is able to send a specially crafted packet to crash a Kerberos server. The kg_unseal_v1 and kg_unseal_v1_iov functions in GSSAPI are reachable externally, and do not handle issues like handling of invalid RFC 1964 to
Bugzilla
CVE-2014-4342 CVE-2014-4341 krb5: denial of service flaws when handling RFC 1964 tokens [fedora-all]
bugzilla·2014-07-04·CVSS 5.0
CVE-2014-4342 [MEDIUM] CVE-2014-4342 CVE-2014-4341 krb5: denial of service flaws when handling RFC 1964 tokens [fedora-all]
CVE-2014-4342 CVE-2014-4341 krb5: denial of service flaws when handling RFC 1964 tokens [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this
Bugzilla
CVE-2014-4341 krb5: denial of service flaws when handling padding length longer than the plaintext
bugzilla·2014-07-04·CVSS 5.0
CVE-2014-4341 [MEDIUM] CVE-2014-4341 krb5: denial of service flaws when handling padding length longer than the plaintext
CVE-2014-4341 krb5: denial of service flaws when handling padding length longer than the plaintext
Flaws were found in the way MIT Kerberos handled RFC 1964 tokens. A man-in-the-middle attacker able to inject packets into an application's GSS-API session could use this flaw to crash the application.
References:
http://diswww.mit.edu:8008/menelaus.mit.edu/cvs-krb5/28388
https://github.com/krb5/krb5/commit/fb99962cbd063ac04c9a9d2cc7c75eab73f3533d
Discussion:
Created krb5 tracking bugs for this issue:
Affects: fedora-all [bug 1116181]
---
There are two distinct flaws in krb5:
CVE-2014-4341: Affects all shipped versions of krb5 package.
CVE-2014-4342: Affects only krb5-1.7 and later.
Hence it makes more sense to split this bug into two parts.
We will use this flaw for CVE-2014-4341.
http://advisories.mageia.org/MGASA-2014-0345.htmlhttp://krbdev.mit.edu/rt/Ticket/Display.html?id=7949http://rhn.redhat.com/errata/RHSA-2015-0439.htmlhttp://secunia.com/advisories/59102http://secunia.com/advisories/60082http://www.debian.org/security/2014/dsa-3000http://www.mandriva.com/security/advisories?name=MDVSA-2014:165http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/68908http://www.securitytracker.com/id/1030706https://exchange.xforce.ibmcloud.com/vulnerabilities/94903https://github.com/krb5/krb5/commit/e6ae703ae597d798e310368d52b8f38ee11c6a73http://advisories.mageia.org/MGASA-2014-0345.htmlhttp://krbdev.mit.edu/rt/Ticket/Display.html?id=7949http://rhn.redhat.com/errata/RHSA-2015-0439.htmlhttp://secunia.com/advisories/59102http://secunia.com/advisories/60082http://www.debian.org/security/2014/dsa-3000http://www.mandriva.com/security/advisories?name=MDVSA-2014:165http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/68908http://www.securitytracker.com/id/1030706https://exchange.xforce.ibmcloud.com/vulnerabilities/94903https://github.com/krb5/krb5/commit/e6ae703ae597d798e310368d52b8f38ee11c6a73
2014-07-20
Published