5
CVSSv2

CVE-2014-9423

Published: 19/02/2015 Updated: 21/01/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x up to and including 1.11.5, 1.12.x up to and including 1.12.2, and 1.13.x prior to 1.13.1 transmits uninitialized interposer data to clients, which allows remote malicious users to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mit kerberos 5 1.11

mit kerberos 5 1.12.2

mit kerberos 5 1.13

mit kerberos 5 1.12

mit kerberos 5 1.12.1

mit kerberos 5 1.11.3

mit kerberos 5 1.11.4

mit kerberos 5 1.11.5

mit kerberos 5 1.11.1

mit kerberos 5 1.11.2

Vendor Advisories

Several security issues were fixed in Kerberos ...
An information disclosure flaw was found in the way MIT Kerberos RPCSEC_GSS implementation (libgssrpc) handled certain requests An attacker could send a specially crafted request to an application using libgssrpc to disclose a limited portion of uninitialized memory used by that application ...