Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9423

Опубликовано: 19 фев. 2015
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

РелизСтатусПримечание
devel

released

1.12.1+dfsg-17
esm-infra-legacy/trusty

not-affected

1.12+dfsg-2ubuntu5.1
lucid

released

1.8.1+dfsg-2ubuntu0.14
precise

released

1.10+dfsg~beta1-2ubuntu0.6
trusty

released

1.12+dfsg-2ubuntu5.1
trusty/esm

not-affected

1.12+dfsg-2ubuntu5.1
upstream

released

1.12.1+dfsg-17
utopic

released

1.12.1+dfsg-10ubuntu0.1

Показывать по

EPSS

Процентиль: 80%
0.01514
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

nvd
больше 10 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

debian
больше 10 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c ...

github
больше 3 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

suse-cvrf
больше 10 лет назад

Security update for krb5

EPSS

Процентиль: 80%
0.01514
Низкий

5 Medium

CVSS2