MIT kerberos 5 'ldap _ principal2.c' Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
MIT Kerberos 5 1.6-1.12.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69168
CVE (CAN) ID: CVE-2014-4345
Kerberos is a widely used super-powerful encryption to verify the network protocol between the client and the server.
The implementation of MIT kerberos 5 1.6-1.12.1 has a buffer overflow vulnerability. When the KDC database is configured to use LDAP, authenticated remote attackers can exploit this vulnerability to write data across borders, attackers can execute arbitrary code in the current user context.
<* Source: Tomas Kuthan
Link: http://seclists.org/bugtraq/2014/Aug/65
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MIT
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://web.mit.edu/kerberos/www/advisories/index.html
This article permanently updates the link address: