Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9423

Опубликовано: 19 фев. 2015
Источник: ubuntu
Приоритет: low
CVSS2: 5

Описание

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

РелизСтатусПримечание
devel

released

1.12.1+dfsg-17
esm-infra-legacy/trusty

released

1.12+dfsg-2ubuntu5.1
lucid

released

1.8.1+dfsg-2ubuntu0.14
precise

released

1.10+dfsg~beta1-2ubuntu0.6
trusty

released

1.12+dfsg-2ubuntu5.1
trusty/esm

released

1.12+dfsg-2ubuntu5.1
upstream

released

1.12.1+dfsg-17
utopic

released

1.12.1+dfsg-10ubuntu0.1

Показывать по

5 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

nvd
почти 11 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

debian
почти 11 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c ...

github
больше 3 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

suse-cvrf
около 11 лет назад

Security update for krb5

5 Medium

CVSS2