CVE-2014-4344
published 2014-08-14CVE-2014-4344: The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows…
PriorityP336high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
6.61%
93.1th percentile
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty continuation token at a certain point during a SPNEGO negotiation.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | krb5 | < krb5 1.12.1+dfsg-5 (bookworm) | krb5 1.12.1+dfsg-5 (bookworm) |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | — | — |
| mit | krb5 | >= 0 < 1.12.1+dfsg-5 | 1.12.1+dfsg-5 |
| mit | krb5 | >= 0 < 1.12.1+dfsg-5 | 1.12.1+dfsg-5 |
| mit | krb5 | >= 0 < 1.12.1+dfsg-5 | 1.12.1+dfsg-5 |
| mit | krb5 | >= 0 < 1.12.1+dfsg-5 | 1.12.1+dfsg-5 |
| mit | krb5 | >= 0 < 1.12+dfsg-2ubuntu4.2 | 1.12+dfsg-2ubuntu4.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Kerberos vulnerabilities
vendor_ubuntu·2014-08-11·CVSS 5.0
CVE-2012-1016 [MEDIUM] Kerberos vulnerabilities
Title: Kerberos vulnerabilities
Summary: Several security issues were fixed in Kerberos.
It was discovered that Kerberos incorrectly handled certain crafted Draft 9
requests. A remote attacker could use this issue to cause the daemon to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-1016)
It was discovered that Kerberos incorrectly handled certain malformed
KRB5_PADATA_PK_AS_REQ AS-REQ requests. A remote attacker could use this
issue to cause the daemon to crash, resulting in a denial of service. This
issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS. (CVE-2013-1415)
It was discovered that Kerberos incorrectly handled certain crafted TGS-REQ
requests. A remote authenticated attacker could use this issue to cause the
daemon to crash
Red Hat
krb5: NULL pointer dereference flaw in SPNEGO acceptor for continuation tokens
vendor_redhat·2014-07-15·CVSS 7.8
CVE-2014-4344 [HIGH] CWE-476 krb5: NULL pointer dereference flaw in SPNEGO acceptor for continuation tokens
krb5: NULL pointer dereference flaw in SPNEGO acceptor for continuation tokens
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty continuation token at a certain point during a SPNEGO negotiation.
A NULL pointer dereference flaw was found in the MIT Kerberos SPNEGO acceptor for continuation tokens. A remote, unauthenticated attacker could use this flaw to crash a GSSAPI-enabled server application.
Debian
CVE-2014-4344: krb5 - The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mec...
vendor_debian·2014·CVSS 7.8
CVE-2014-4344 [HIGH] CVE-2014-4344: krb5 - The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mec...
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty continuation token at a certain point during a SPNEGO negotiation.
Scope: local
bookworm: resolved (fixed in 1.12.1+dfsg-5)
bullseye: resolved (fixed in 1.12.1+dfsg-5)
forky: resolved (fixed in 1.12.1+dfsg-5)
sid: resolved (fixed in 1.12.1+dfsg-5)
trixie: resolved (fixed in 1.12.1+dfsg-5)
GHSA
GHSA-335x-2h4v-298w: The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech
ghsa_unreviewed·2022-05-13
CVE-2014-4344 [HIGH] CWE-476 GHSA-335x-2h4v-298w: The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty continuation token at a certain point during a SPNEGO negotiation.
OSV
CVE-2014-4344: The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech
osv·2014-08-14·CVSS 7.8
CVE-2014-4344 [HIGH] CVE-2014-4344: The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty continuation token at a certain point during a SPNEGO negotiation.
OSV
krb5 vulnerabilities
osv·2014-08-11·CVSS 5.0
CVE-2012-1016 [MEDIUM] krb5 vulnerabilities
krb5 vulnerabilities
It was discovered that Kerberos incorrectly handled certain crafted Draft 9
requests. A remote attacker could use this issue to cause the daemon to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2012-1016)
It was discovered that Kerberos incorrectly handled certain malformed
KRB5_PADATA_PK_AS_REQ AS-REQ requests. A remote attacker could use this
issue to cause the daemon to crash, resulting in a denial of service. This
issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS. (CVE-2013-1415)
It was discovered that Kerberos incorrectly handled certain crafted TGS-REQ
requests. A remote authenticated attacker could use this issue to cause the
daemon to crash, resulting in a denial of service. This issue only affected
Ubuntu 1
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4343 CVE-2014-4344 krb5: various flaws [fedora-all]
bugzilla·2014-07-22·CVSS 7.6
CVE-2014-4343 [HIGH] CVE-2014-4343 CVE-2014-4344 krb5: various flaws [fedora-all]
CVE-2014-4343 CVE-2014-4344 krb5: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While onl
Bugzilla
CVE-2014-4344 krb5: NULL pointer dereference flaw in SPNEGO acceptor for continuation tokens
bugzilla·2014-07-22·CVSS 7.8
CVE-2014-4344 [HIGH] CVE-2014-4344 krb5: NULL pointer dereference flaw in SPNEGO acceptor for continuation tokens
CVE-2014-4344 krb5: NULL pointer dereference flaw in SPNEGO acceptor for continuation tokens
A NULL pointer dereference flaw was found in the MIT Kerberos SPNEGO acceptor for continuation tokens. An unauthenticated attacker could use this flaw to crash the server acceptor.
It is reported that this issue affects version 1.5 and later.
Upstream commit and further details:
https://github.com/krb5/krb5/commit/524688ce87a15fc75f87efc8c039ba4c7d5c197b
Discussion:
Created krb5 tracking bugs for this issue:
Affects: fedora-all [bug 1121879]
---
Successful exploitation of this flaw requires that attacker must provide at least one valid context token in the security context negotiation before sending the empty token.This can be done using unauthenticated AS-REQ as the first token and then s
http://advisories.mageia.org/MGASA-2014-0345.htmlhttp://aix.software.ibm.com/aix/efixes/security/nas_advisory1.aschttp://krbdev.mit.edu/rt/Ticket/Display.html?id=7970http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136360.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0439.htmlhttp://secunia.com/advisories/59102http://secunia.com/advisories/60082http://secunia.com/advisories/60448http://secunia.com/advisories/61051http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15561.htmlhttp://www.debian.org/security/2014/dsa-3000http://www.mandriva.com/security/advisories?name=MDVSA-2014:165http://www.osvdb.org/109389http://www.securityfocus.com/bid/69160http://www.securitytracker.com/id/1030706https://bugzilla.redhat.com/show_bug.cgi?id=1121877https://exchange.xforce.ibmcloud.com/vulnerabilities/95210https://github.com/krb5/krb5/commit/524688ce87a15fc75f87efc8c039ba4c7d5c197bhttps://github.com/krb5/krb5/commit/a7886f0ed1277c69142b14a2c6629175a6331edchttp://advisories.mageia.org/MGASA-2014-0345.htmlhttp://aix.software.ibm.com/aix/efixes/security/nas_advisory1.aschttp://krbdev.mit.edu/rt/Ticket/Display.html?id=7970http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136360.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0439.htmlhttp://secunia.com/advisories/59102http://secunia.com/advisories/60082http://secunia.com/advisories/60448http://secunia.com/advisories/61051http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15561.htmlhttp://www.debian.org/security/2014/dsa-3000http://www.mandriva.com/security/advisories?name=MDVSA-2014:165http://www.osvdb.org/109389http://www.securityfocus.com/bid/69160http://www.securitytracker.com/id/1030706https://bugzilla.redhat.com/show_bug.cgi?id=1121877https://exchange.xforce.ibmcloud.com/vulnerabilities/95210https://github.com/krb5/krb5/commit/524688ce87a15fc75f87efc8c039ba4c7d5c197bhttps://github.com/krb5/krb5/commit/a7886f0ed1277c69142b14a2c6629175a6331edc
2014-08-14
Published