CVE-2014-5352
krb5 - security update
EPSS 6.2%
描述
The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly maintain security-context handles, which allows remote authenticated users to cause a denial of service (use-after-free and double free, and daemon crash) or possibly execute arbitrary code via crafted GSSAPI traffic, as demonstrated by traffic to kadmind.
如何修補 CVE-2014-5352
要修補 CVE-2014-5352,請將受影響套件升級到下列已修補版本。
- Debian/krb5—升級至 1.12.1+dfsg-17 或更新版本
- —升級至 1.8.3+dfsg-4squeeze9 或更新版本
- —升級至 1.10.1+dfsg-5+deb7u3 或更新版本
CVE-2014-5352 正在被利用嗎?
中等 — EPSS 為 6.2%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 1.12.1+dfsg-17
- from 0, < 1.8.3+dfsg-4squeeze9
- from 0, < 1.10.1+dfsg-5+deb7u3