Lucene search

K
cveMitreCVE-2014-4345
HistoryAug 14, 2014 - 5:01 a.m.

CVE-2014-4345

2014-08-1405:01:50
CWE-189
mitre
web.nvd.nist.gov
55
cve-2014-4345
krb5
remote code execution
buffer overflow
denial of service
ldap kdb module
mit kerberos 5
security vulnerability
nvd

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

9.2

Confidence

High

EPSS

0.013

Percentile

85.9%

Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) 1.6.x through 1.11.x before 1.11.6 and 1.12.x before 1.12.2 allows remote authenticated users to cause a denial of service (buffer overflow) or possibly execute arbitrary code via a series of “cpw -keepold” commands.

Affected configurations

Nvd
Node
mitkerberos_5Match1.6
OR
mitkerberos_5Match1.6.1
OR
mitkerberos_5Match1.6.2
OR
mitkerberos_5Match1.7
OR
mitkerberos_5Match1.7.1
OR
mitkerberos_5Match1.8
OR
mitkerberos_5Match1.8.1
OR
mitkerberos_5Match1.8.2
OR
mitkerberos_5Match1.8.3
OR
mitkerberos_5Match1.8.4
OR
mitkerberos_5Match1.8.5
OR
mitkerberos_5Match1.8.6
OR
mitkerberos_5Match1.9
OR
mitkerberos_5Match1.9.1
OR
mitkerberos_5Match1.9.2
OR
mitkerberos_5Match1.9.3
OR
mitkerberos_5Match1.9.4
OR
mitkerberos_5Match1.10
OR
mitkerberos_5Match1.10.1
OR
mitkerberos_5Match1.10.2
OR
mitkerberos_5Match1.10.3
OR
mitkerberos_5Match1.10.4
OR
mitkerberos_5Match1.11
OR
mitkerberos_5Match1.11.1
OR
mitkerberos_5Match1.11.2
OR
mitkerberos_5Match1.11.3
OR
mitkerberos_5Match1.11.4
OR
mitkerberos_5Match1.11.5
OR
mitkerberos_5Match1.12
OR
mitkerberos_5Match1.12.1
VendorProductVersionCPE
mitkerberos_51.6cpe:2.3:a:mit:kerberos_5:1.6:*:*:*:*:*:*:*
mitkerberos_51.6.1cpe:2.3:a:mit:kerberos_5:1.6.1:*:*:*:*:*:*:*
mitkerberos_51.6.2cpe:2.3:a:mit:kerberos_5:1.6.2:*:*:*:*:*:*:*
mitkerberos_51.7cpe:2.3:a:mit:kerberos_5:1.7:*:*:*:*:*:*:*
mitkerberos_51.7.1cpe:2.3:a:mit:kerberos_5:1.7.1:*:*:*:*:*:*:*
mitkerberos_51.8cpe:2.3:a:mit:kerberos_5:1.8:*:*:*:*:*:*:*
mitkerberos_51.8.1cpe:2.3:a:mit:kerberos_5:1.8.1:*:*:*:*:*:*:*
mitkerberos_51.8.2cpe:2.3:a:mit:kerberos_5:1.8.2:*:*:*:*:*:*:*
mitkerberos_51.8.3cpe:2.3:a:mit:kerberos_5:1.8.3:*:*:*:*:*:*:*
mitkerberos_51.8.4cpe:2.3:a:mit:kerberos_5:1.8.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 301

References

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

9.2

Confidence

High

EPSS

0.013

Percentile

85.9%