1
PublicDateAtUSN: 2015-02-03
2
Candidate: CVE-2014-9421
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9421
6
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
7
https://usn.ubuntu.com/usn/usn-2498-1
9
The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT
10
Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x
11
before 1.13.1 does not properly handle partial XDR deserialization, which
12
allows remote authenticated users to cause a denial of service
13
(use-after-free and double free, and daemon crash) or possibly execute
14
arbitrary code via malformed XDR data, as demonstrated by data sent to
23
Tags_krb5: universe-binary
25
upstream: https://github.com/krb5/krb5/commit/a197e92349a4aa2141b5dff12e9dd44c2a2166e3
26
upstream: http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.txt
27
upstream_krb5: released (1.12.1+dfsg-17)
28
lucid_krb5: released (1.8.1+dfsg-2ubuntu0.14)
29
precise_krb5: released (1.10+dfsg~beta1-2ubuntu0.6)
30
trusty_krb5: released (1.12+dfsg-2ubuntu5.1)
31
utopic_krb5: released (1.12.1+dfsg-10ubuntu0.1)
32
devel_krb5: released (1.12.1+dfsg-17)