MIT kerberos 5 Denial of Service Vulnerability (CVE-2014-4343)
Release date:
Updated on:
Affected Systems:
MIT Kerberos 5 1.6-1.12.1
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-4343
Kerberos is a widely used super-powerful encryption to verify the network protocol between the client and the server.
When processing certain data packets in MIT kerberos 5 1.6-1.12.1, The GSSAPI initiator (client) has a dual release problem. Attackers can exploit this vulnerability to cause application crash or execute arbitrary code.
<* Source: Tomas Kuthan
Link: http://seclists.org/bugtraq/2014/Aug/65
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MIT
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://web.mit.edu/kerberos/www/advisories/index.html
This article permanently updates the link address: