Back to Database
Status published
Medium
CVE-2014-4341
MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers...
Vulnerability Description
MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-4341
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/krb5/krb5/commit/e6ae703ae597d798e310368d52b8f38ee11c6a73
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94904
- http://aix.software.ibm.com/aix/efixes/security/nas_advisory1.asc
- http://rhn.redhat.com/errata/RHSA-2015-0439.html
- http://secunia.com/advisories/60448
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136360.html
- http://www.securityfocus.com/bid/68909
- http://krbdev.mit.edu/rt/Ticket/Display.html?id=7949
- http://www.debian.org/security/2014/dsa-3000
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:165
- http://security.gentoo.org/glsa/glsa-201412-53.xml
- http://www.securitytracker.com/id/1030706
- http://secunia.com/advisories/60082
- http://advisories.mageia.org/MGASA-2014-0345.html
- http://secunia.com/advisories/59102
More from mit
View All →CVE-2022-42898
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4...
Unknown
0
CVE-2021-37750
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka...
Medium
6.5
CVE-2021-36222
ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in...
High
7.5
CVE-2021-32471
Insufficient input validation in the Marvin Minsky 1967 implementation of...
High
7.8
CVE-2020-28196
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before...
Unknown
0
Affected Vendor
Affected Software
kerberos 5, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux tus, enterprise linux workstation, debian linux, fedora
Vulnerable Versions:
0, 7.0, 7.3, 7.4, 7.5, 7.6, 7.7, 20
Timeline
Official Publish:
July 20th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.