Lucene search

K
cveMitreCVE-2014-9423
HistoryFeb 19, 2015 - 11:59 a.m.

CVE-2014-9423

2015-02-1911:59:07
CWE-200
mitre
web.nvd.nist.gov
55
mit kerberos
vulnerability
cve-2014-9423
remote attack
process heap memory
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0.008

Percentile

82.2%

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.

Affected configurations

Nvd
Node
mitkerberos_5Match1.11
OR
mitkerberos_5Match1.11.1
OR
mitkerberos_5Match1.11.2
OR
mitkerberos_5Match1.11.3
OR
mitkerberos_5Match1.11.4
OR
mitkerberos_5Match1.11.5
OR
mitkerberos_5Match1.12
OR
mitkerberos_5Match1.12.1
OR
mitkerberos_5Match1.12.2
OR
mitkerberos_5Match1.13
VendorProductVersionCPE
mitkerberos_51.11cpe:2.3:a:mit:kerberos_5:1.11:*:*:*:*:*:*:*
mitkerberos_51.11.1cpe:2.3:a:mit:kerberos_5:1.11.1:*:*:*:*:*:*:*
mitkerberos_51.11.2cpe:2.3:a:mit:kerberos_5:1.11.2:*:*:*:*:*:*:*
mitkerberos_51.11.3cpe:2.3:a:mit:kerberos_5:1.11.3:*:*:*:*:*:*:*
mitkerberos_51.11.4cpe:2.3:a:mit:kerberos_5:1.11.4:*:*:*:*:*:*:*
mitkerberos_51.11.5cpe:2.3:a:mit:kerberos_5:1.11.5:*:*:*:*:*:*:*
mitkerberos_51.12cpe:2.3:a:mit:kerberos_5:1.12:*:*:*:*:*:*:*
mitkerberos_51.12.1cpe:2.3:a:mit:kerberos_5:1.12.1:*:*:*:*:*:*:*
mitkerberos_51.12.2cpe:2.3:a:mit:kerberos_5:1.12.2:*:*:*:*:*:*:*
mitkerberos_51.13cpe:2.3:a:mit:kerberos_5:1.13:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0.008

Percentile

82.2%