FreeBSD : krb5 1.12 -- New release/fix multiple vulnerabilities (63527d0d-b9de-11e4-8a48-206a8a720317)

high Nessus Plugin ID 81432

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The MIT Kerberos team announces the availability of MIT Kerberos 5 Release 1.12.3 :

Fix multiple vulnerabilities in the LDAP KDC back end. [CVE-2014-5354] [CVE-2014-5353]

Fix multiple kadmind vulnerabilities, some of which are based in the gssrpc library. [CVE-2014-5352 CVE-2014-5352 CVE-2014-9421 CVE-2014-9422 CVE-2014-9423]

Solution

Update the affected package.

See Also

http://web.mit.edu/kerberos/krb5-1.12/README-1.12.3.txt

http://www.nessus.org/u?926682e4

Plugin Details

Severity: High

ID: 81432

File Name: freebsd_pkg_63527d0db9de11e48a48206a8a720317.nasl

Version: 1.4

Type: local

Published: 2/23/2015

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:krb5-112, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2/21/2015

Vulnerability Publication Date: 2/20/2015