CVE-2014-4343
published 2014-08-14CVE-2014-4343: Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x…
PriorityP343high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
6.42%
92.9th percentile
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies a security mechanism different from the one proposed by the initiator.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | krb5 | < krb5 1.12.1+dfsg-5 (bookworm) | krb5 1.12.1+dfsg-5 (bookworm) |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | krb5 | >= 0 < 1.12.1+dfsg-5 | 1.12.1+dfsg-5 |
| mit | krb5 | >= 0 < 1.12.1+dfsg-5 | 1.12.1+dfsg-5 |
| mit | krb5 | >= 0 < 1.12.1+dfsg-5 | 1.12.1+dfsg-5 |
| mit | krb5 | >= 0 < 1.12.1+dfsg-5 | 1.12.1+dfsg-5 |
| mit | krb5 | >= 0 < 1.12+dfsg-2ubuntu4.2 | 1.12+dfsg-2ubuntu4.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.6HIGH
vendor_debian7.6HIGH
vendor_redhat7.6HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cmrr-h89w-fc55: Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech
ghsa_unreviewed·2022-05-13
CVE-2014-4343 [HIGH] CWE-415 GHSA-cmrr-h89w-fc55: Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies a security mechanism different from the one proposed by the initiator.
OSV
CVE-2014-4343: Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech
osv·2014-08-14·CVSS 7.6
CVE-2014-4343 [HIGH] CVE-2014-4343: Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies a security mechanism different from the one proposed by the initiator.
OSV
krb5 vulnerabilities
osv·2014-08-11·CVSS 5.0
CVE-2012-1016 [MEDIUM] krb5 vulnerabilities
krb5 vulnerabilities
It was discovered that Kerberos incorrectly handled certain crafted Draft 9
requests. A remote attacker could use this issue to cause the daemon to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-1016)
It was discovered that Kerberos incorrectly handled certain malformed
KRB5_PADATA_PK_AS_REQ AS-REQ requests. A remote attacker could use this
issue to cause the daemon to crash, resulting in a denial of service. This
issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS. (CVE-2013-1415)
It was discovered that Kerberos incorrectly handled certain crafted TGS-REQ
requests. A remote authenticated attacker could use this issue to cause the
daemon to crash, resulting in a denial of service. This issue only affected
Ubuntu 1
Ubuntu
Kerberos vulnerabilities
vendor_ubuntu·2014-08-11·CVSS 5.0
CVE-2012-1016 [MEDIUM] Kerberos vulnerabilities
Title: Kerberos vulnerabilities
Summary: Several security issues were fixed in Kerberos.
It was discovered that Kerberos incorrectly handled certain crafted Draft 9
requests. A remote attacker could use this issue to cause the daemon to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-1016)
It was discovered that Kerberos incorrectly handled certain malformed
KRB5_PADATA_PK_AS_REQ AS-REQ requests. A remote attacker could use this
issue to cause the daemon to crash, resulting in a denial of service. This
issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS. (CVE-2013-1415)
It was discovered that Kerberos incorrectly handled certain crafted TGS-REQ
requests. A remote authenticated attacker could use this issue to cause the
daemon to crash
Red Hat
krb5: double-free flaw in SPNEGO initiators
vendor_redhat·2014-07-15·CVSS 7.6
CVE-2014-4343 [HIGH] CWE-416 krb5: double-free flaw in SPNEGO initiators
krb5: double-free flaw in SPNEGO initiators
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies a security mechanism different from the one proposed by the initiator.
A double-free flaw was found in the MIT Kerberos SPNEGO initiators. An attacker able to spoof packets to appear as though they are from an GSSAPI acceptor could use this flaw to crash a client application that uses MIT Kerberos.
Statement: This issue did not affect the version of krb5 as shipped with Red Ha
Debian
CVE-2014-4343: krb5 - Double free vulnerability in the init_ctx_reselect function in the SPNEGO initia...
vendor_debian·2014·CVSS 7.6
CVE-2014-4343 [HIGH] CVE-2014-4343: krb5 - Double free vulnerability in the init_ctx_reselect function in the SPNEGO initia...
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies a security mechanism different from the one proposed by the initiator.
Scope: local
bookworm: resolved (fixed in 1.12.1+dfsg-5)
bullseye: resolved (fixed in 1.12.1+dfsg-5)
forky: resolved (fixed in 1.12.1+dfsg-5)
sid: resolved (fixed in 1.12.1+dfsg-5)
trixie: resolved (fixed in 1.12.1+dfsg-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4343 CVE-2014-4344 krb5: various flaws [fedora-all]
bugzilla·2014-07-22·CVSS 7.6
CVE-2014-4343 [HIGH] CVE-2014-4343 CVE-2014-4344 krb5: various flaws [fedora-all]
CVE-2014-4343 CVE-2014-4344 krb5: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While onl
Bugzilla
CVE-2014-4343 krb5: double-free flaw in SPNEGO initiators
bugzilla·2014-07-22·CVSS 7.6
CVE-2014-4343 [HIGH] CVE-2014-4343 krb5: double-free flaw in SPNEGO initiators
CVE-2014-4343 krb5: double-free flaw in SPNEGO initiators
A double-free flaw was found in the MIT Kerberos SPNEGO initiators. An attacker able to spoof packets to appear as though they are from an GSSAPI acceptor could use this flaw to crash a client application that uses MIT Kerberos.
It is reported that this issue affects version 1.10 and later.
Upstream commit and further details:
https://github.com/krb5/krb5/commit/f18ddf5d82de0ab7591a36e465bc24225776940f
Discussion:
Created krb5 tracking bugs for this issue:
Affects: fedora-all [bug 1121879]
---
spnego_gss_init_sec_context -> init_ctx_cont -> init_ctx_nego -> init_ctx_reselect
It is possible for unauthenticated attacker to crash the clients, as in the process according to RFC SPNEGO uses pseudo-mechanism which checks which g
Bugzilla
CVE-2014-4343: use-after-free crash in SPNEGO
bugzilla·2014-07-21·CVSS 7.6
CVE-2014-4343 [HIGH] CVE-2014-4343: use-after-free crash in SPNEGO
CVE-2014-4343: use-after-free crash in SPNEGO
+++ This bug was initially created as a clone of Bug #1117963 +++
I'm trying to use firefox to authenticate to an internal web site. Like *many* internal web sites, this one doesn't have correct reverse DNS so Kerberos doesn't get the right SPN and fails to get a ticket for it.
That doesn't stop it from trying *something*, and screwing up my NTLM auth that would have succeeded....
First it sends a request with no Authorization: header, gets back a 401 with
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
Then it sends this:Authorization: Negotiate YIIP1wYGKwYBBQUCoIIPyzCCD8egFjAUBgYrBgEFAgUGCisGAQQBgjcCAgqigg+rBIIPp2CCD6MGBisGAQUCBQUBMBahFAQSR0VSLkNPUlAuSU5URUwuQ09NbIIPfTCCD3mhAwIBBaIDAgEMo4IO/jCCDvowgg4eoQMCAQGigg4VBIIOEW6CDg0wgg4JoAMC
http://advisories.mageia.org/MGASA-2014-0345.htmlhttp://aix.software.ibm.com/aix/efixes/security/nas_advisory1.aschttp://krbdev.mit.edu/rt/Ticket/Display.html?id=7969http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136360.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0439.htmlhttp://secunia.com/advisories/59102http://secunia.com/advisories/60082http://secunia.com/advisories/60448http://secunia.com/advisories/61052http://security.gentoo.org/glsa/glsa-201412-53.xmlhttp://support.f5.com/kb/en-us/solutions/public/15000/500/sol15553.htmlhttp://www.debian.org/security/2014/dsa-3000http://www.osvdb.org/109390http://www.securityfocus.com/bid/69159http://www.securitytracker.com/id/1030706https://bugzilla.redhat.com/show_bug.cgi?id=1121876https://exchange.xforce.ibmcloud.com/vulnerabilities/95211https://github.com/krb5/krb5/commit/f18ddf5d82de0ab7591a36e465bc24225776940fhttp://advisories.mageia.org/MGASA-2014-0345.htmlhttp://aix.software.ibm.com/aix/efixes/security/nas_advisory1.aschttp://krbdev.mit.edu/rt/Ticket/Display.html?id=7969http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136360.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0439.htmlhttp://secunia.com/advisories/59102http://secunia.com/advisories/60082http://secunia.com/advisories/60448http://secunia.com/advisories/61052http://security.gentoo.org/glsa/glsa-201412-53.xmlhttp://support.f5.com/kb/en-us/solutions/public/15000/500/sol15553.htmlhttp://www.debian.org/security/2014/dsa-3000http://www.osvdb.org/109390http://www.securityfocus.com/bid/69159http://www.securitytracker.com/id/1030706https://bugzilla.redhat.com/show_bug.cgi?id=1121876https://exchange.xforce.ibmcloud.com/vulnerabilities/95211https://github.com/krb5/krb5/commit/f18ddf5d82de0ab7591a36e465bc24225776940f
2014-08-14
Published