CVE-2014-5354NULL Pointer Dereference in Kerberos

Severity
3.5LOWNVD
EPSS
0.5%
top 32.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 13

Description

plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by creating a database entry for a keyless principal, as demonstrated by a kadmin "add_principal -nokey" or "purgekeys -all" command.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 6.8 | Impact: 2.9

Affected Packages3 packages

Debianmit/krb5< 1.12.1+dfsg-16+3
NVDmit/kerberos5_1.13
NVDmit/kerberos_51.12, 1.12.1, 1.12.2+2

🔴Vulnerability Details

3
GHSA
GHSA-m892-8m95-539h: plugins/kdb/ldap/libkdb_ldap/ldap_principal22022-05-13
OSV
CVE-2014-5354: plugins/kdb/ldap/libkdb_ldap/ldap_principal22014-12-16
CVEList
CVE-2014-5354: plugins/kdb/ldap/libkdb_ldap/ldap_principal22014-12-16

📋Vendor Advisories

3
Ubuntu
Kerberos vulnerabilities2015-02-10
Red Hat
krb5: NULL pointer dereference when using keyless entries2014-11-20
Debian
CVE-2014-5354: krb5 - plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12...2014

💬Community

2
Bugzilla
CVE-2014-5354 krb5: NULL pointer dereference when using keyless entries [fedora-21]2014-12-19
Bugzilla
CVE-2014-5354 krb5: NULL pointer dereference when using keyless entries2014-12-16
CVE-2014-5354 — NULL Pointer Dereference in Kerberos | cvebase