Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-4345

Опубликовано: 14 авг. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 8.5

Описание

Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) 1.6.x through 1.11.x before 1.11.6 and 1.12.x before 1.12.2 allows remote authenticated users to cause a denial of service (buffer overflow) or possibly execute arbitrary code via a series of "cpw -keepold" commands.

РелизСтатусПримечание
devel

not-affected

1.12.1+dfsg-7
esm-infra-legacy/trusty

not-affected

1.12+dfsg-2ubuntu4.2
lucid

released

1.8.1+dfsg-2ubuntu0.13
precise

released

1.10+dfsg~beta1-2ubuntu0.5
trusty

released

1.12+dfsg-2ubuntu4.2
trusty/esm

not-affected

1.12+dfsg-2ubuntu4.2
upstream

needs-triage

Показывать по

EPSS

Процентиль: 90%
0.05664
Низкий

8.5 High

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) 1.6.x through 1.11.x before 1.11.6 and 1.12.x before 1.12.2 allows remote authenticated users to cause a denial of service (buffer overflow) or possibly execute arbitrary code via a series of "cpw -keepold" commands.

nvd
около 11 лет назад

Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) 1.6.x through 1.11.x before 1.11.6 and 1.12.x before 1.12.2 allows remote authenticated users to cause a denial of service (buffer overflow) or possibly execute arbitrary code via a series of "cpw -keepold" commands.

debian
около 11 лет назад

Off-by-one error in the krb5_encode_krbsecretkey function in plugins/k ...

github
больше 3 лет назад

Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) 1.6.x through 1.11.x before 1.11.6 and 1.12.x before 1.12.2 allows remote authenticated users to cause a denial of service (buffer overflow) or possibly execute arbitrary code via a series of "cpw -keepold" commands.

oracle-oval
почти 11 лет назад

ELSA-2014-1255: krb5 security update (MODERATE)

EPSS

Процентиль: 90%
0.05664
Низкий

8.5 High

CVSS2