Mandriva Linux Security Advisory : krb5 (MDVSA-2014:165)

high Nessus Plugin ID 77644

Synopsis

The remote Mandriva Linux host is missing one or more security updates.

Description

Updated krb5 package fixes security vulnerabilities :

MIT Kerberos 5 allows attackers to cause a denial of service via a buffer over-read or NULL pointer dereference, by injecting invalid tokens into a GSSAPI application session (CVE-2014-4341, CVE-2014-4342).

MIT Kerberos 5 allows attackers to cause a denial of service via a double-free flaw or NULL pointer dereference, while processing invalid SPNEGO tokens (CVE-2014-4344).

In MIT Kerberos 5, when kadmind is configured to use LDAP for the KDC database, an authenticated remote attacker can cause it to perform an out-of-bounds write (buffer overflow) (CVE-2014-4345).

Solution

Update the affected packages.

See Also

http://advisories.mageia.org/MGASA-2014-0345.html

Plugin Details

Severity: High

ID: 77644

File Name: mandriva_MDVSA-2014-165.nasl

Version: 1.7

Type: local

Published: 9/12/2014

Updated: 1/6/2021

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 7.4

Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Temporal Vector: E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:krb5, p-cpe:/a:mandriva:linux:krb5-pkinit-openssl, p-cpe:/a:mandriva:linux:krb5-server, p-cpe:/a:mandriva:linux:krb5-server-ldap, p-cpe:/a:mandriva:linux:krb5-workstation, p-cpe:/a:mandriva:linux:lib64krb53, p-cpe:/a:mandriva:linux:lib64krb53-devel, cpe:/o:mandriva:business_server:1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/2/2014

Reference Information

CVE: CVE-2014-4341, CVE-2014-4342, CVE-2014-4344, CVE-2014-4345

BID: 68908, 68909, 69160, 69168

MDVSA: 2014:165