Логотип exploitDog
bind:"GHSA-c8r5-76c4-8w9w" OR bind:"CVE-2014-9423"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-c8r5-76c4-8w9w" OR bind:"CVE-2014-9423"

Количество 9

Количество 9

github логотип

GHSA-c8r5-76c4-8w9w

больше 3 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

EPSS: Низкий
ubuntu логотип

CVE-2014-9423

больше 10 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2014-9423

больше 10 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-9423

больше 10 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-9423

больше 10 лет назад

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c ...

CVSS2: 5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:0257-1

больше 10 лет назад

Security update for krb5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:0290-2

больше 10 лет назад

Security update for krb5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:0290-1

больше 10 лет назад

Security update for krb5

EPSS: Низкий
oracle-oval логотип

ELSA-2015-0439

больше 10 лет назад

ELSA-2015-0439: krb5 security, bug fix and enhancement update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-c8r5-76c4-8w9w

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

2%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2014-9423

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

CVSS2: 5
2%
Низкий
больше 10 лет назад
redhat логотип
CVE-2014-9423

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

CVSS2: 5
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-9423

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

CVSS2: 5
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9423

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c ...

CVSS2: 5
2%
Низкий
больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:0257-1

Security update for krb5

больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:0290-2

Security update for krb5

больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:0290-1

Security update for krb5

больше 10 лет назад
oracle-oval логотип
ELSA-2015-0439

ELSA-2015-0439: krb5 security, bug fix and enhancement update (MODERATE)

больше 10 лет назад

Уязвимостей на страницу