Information disclosure in Kerberos 5 - CVE-2014-9423

 

Information disclosure in Kerberos 5 - CVE-2014-9423

Published: February 19, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40886
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-9423
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.


Affected software

Kerberos 5
SUSE Linux
Fedora
krb5

How to mitigate CVE-2014-9423

Install update from vendor's website.

krb5 - update to 1.12.2-14.fc21

External References

Related Security Bulletins