MIT Kerberos 5 Denial of Service Vulnerability (CVE-2014-4341)
Release date:
Updated on:
Affected Systems:
MIT Kerberos 1.7.x-1.12.x
MIT Kerberos
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-4341
Kerberos is a widely used super-powerful encryption to verify the network protocol between the client and the server.
The implementation of MIT Kerberos 5 (krb5) versions earlier than 1.12.2 has a denial of service vulnerability. Remote attackers inject invalid tokens into the GSSAPI application session, this vulnerability can cause buffer overflow or indirect reference by a null pointer, resulting in application crash.
<* Source: tlyu
Link: http://krbdev.mit.edu/rt/Ticket/Display.html? Id = 7949
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MIT
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://krbdev.mit.edu/rt/Ticket/Display.html? Id = 7949
Https://github.com/krb5/krb5/commit/e6ae703ae597d798e310368d52b8f38ee11c6a73
This article permanently updates the link address: