Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-4341

Опубликовано: 26 июн. 2014
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.

A buffer over-read flaw was found in the way MIT Kerberos handled certain requests. A remote, unauthenticated attacker who is able to inject packets into a client or server application's GSSAPI session could use this flaw to crash the application.

Дополнительная информация

Статус:

Low
Дефект:
CWE-130->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1116180krb5: denial of service flaws when handling padding length longer than the plaintext

EPSS

Процентиль: 94%
0.1261
Средний

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.

nvd
около 11 лет назад

MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.

debian
около 11 лет назад

MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cau ...

github
больше 3 лет назад

MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.

oracle-oval
почти 11 лет назад

ELSA-2014-1245: krb5 security and bug fix update (MODERATE)

EPSS

Процентиль: 94%
0.1261
Средний

4.3 Medium

CVSS2