CVE-2014-9421

The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly handle partial XDR deserialization, which allows remote authenticated users to cause a denial of service (use-after-free and double free, and daemon crash) or possibly execute arbitrary code via malformed XDR data, as demonstrated by data sent to kadmind.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
mitkerberos_5
1.11
mitkerberos_5
1.11.1
mitkerberos_5
1.11.2
mitkerberos_5
1.11.3
mitkerberos_5
1.11.4
mitkerberos_5
1.11.5
mitkerberos_5
1.12
mitkerberos_5
1.12.1
mitkerberos_5
1.12.2
mitkerberos_5
1.13
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
krb5
bullseye (security)
1.18.3-6+deb11u5
fixed
bullseye
1.18.3-6+deb11u5
fixed
bookworm
1.20.1-2+deb12u2
fixed
bookworm (security)
1.20.1-2+deb12u2
fixed
sid
1.21.3-3
fixed
trixie
1.21.3-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
krb5
utopic
Fixed 1.12.1+dfsg-10ubuntu0.1
released
trusty
Fixed 1.12+dfsg-2ubuntu5.1
released
precise
Fixed 1.10+dfsg~beta1-2ubuntu0.6
released
lucid
Fixed 1.8.1+dfsg-2ubuntu0.14
released
References