Mandriva Linux Security Advisory : krb5 (MDVSA-2014:165)

This script is Copyright (C) 2014-2015 Tenable Network Security, Inc.


Synopsis :

The remote Mandriva Linux host is missing one or more security
updates.

Description :

Updated krb5 package fixes security vulnerabilities :

MIT Kerberos 5 allows attackers to cause a denial of service via a
buffer over-read or NULL pointer dereference, by injecting invalid
tokens into a GSSAPI application session (CVE-2014-4341,
CVE-2014-4342).

MIT Kerberos 5 allows attackers to cause a denial of service via a
double-free flaw or NULL pointer dereference, while processing invalid
SPNEGO tokens (CVE-2014-4344).

In MIT Kerberos 5, when kadmind is configured to use LDAP for the KDC
database, an authenticated remote attacker can cause it to perform an
out-of-bounds write (buffer overflow) (CVE-2014-4345).

See also :

http://advisories.mageia.org/MGASA-2014-0345.html

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 8.5
(CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)
CVSS Temporal Score : 7.4
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Mandriva Local Security Checks

Nessus Plugin ID: 77644 ()

Bugtraq ID: 68908
68909
69160
69168

CVE ID: CVE-2014-4341
CVE-2014-4342
CVE-2014-4344
CVE-2014-4345

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now