Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-9423
HistoryFeb 03, 2015 - 12:00 a.m.

CVE-2014-9423

2015-02-0300:00:00
ubuntu.com
ubuntu.com
9

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.008

Percentile

82.2%

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in
MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and
1.13.x before 1.13.1 transmits uninitialized interposer data to clients,
which allows remote attackers to obtain sensitive information from process
heap memory by sniffing the network for data in a handle field.

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchkrb5< 1.8.1+dfsg-2ubuntu0.14UNKNOWN
ubuntu12.04noarchkrb5< 1.10+dfsg~beta1-2ubuntu0.6UNKNOWN
ubuntu14.04noarchkrb5< 1.12+dfsg-2ubuntu5.1UNKNOWN
ubuntu14.10noarchkrb5< 1.12.1+dfsg-10ubuntu0.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.008

Percentile

82.2%