Lucene search

K
centosCentOS ProjectCESA-2014:1255
HistoryOct 10, 2014 - 9:45 p.m.

krb5 security update

2014-10-1021:45:06
CentOS Project
lists.centos.org
65

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

9.8

Confidence

High

EPSS

0.013

Percentile

85.9%

CentOS Errata and Security Advisory CESA-2014:1255

Kerberos is an authentication system which allows clients and services to
authenticate to each other with the help of a trusted third party, a
Kerberos Key Distribution Center (KDC).

A buffer overflow was found in the KADM5 administration server (kadmind)
when it was used with an LDAP back end for the KDC database. A remote,
authenticated attacker could potentially use this flaw to execute arbitrary
code on the system running kadmind. (CVE-2014-4345)

All krb5 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, the krb5kdc and kadmind daemons will be restarted
automatically.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2014-October/082840.html

Affected packages:
krb5-devel
krb5-libs
krb5-server
krb5-server-ldap
krb5-workstation

Upstream details at:
https://access.redhat.com/errata/RHSA-2014:1255

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

9.8

Confidence

High

EPSS

0.013

Percentile

85.9%