FreeBSD : krb5 1.11 -- New release/fix multiple vulnerabilities (dbf9e66c-bd50-11e4-a7ba-206a8a720317)

High Nessus Plugin ID 81534


The remote FreeBSD host is missing a security-related update.


The MIT Kerberos team announces the availability of MIT Kerberos 5 Release 1.11.6 :

Handle certain invalid RFC 1964 GSS tokens correctly to avoid invalid memory reference vulnerabilities. [CVE-2014-4341

Fix memory management vulnerabilities in GSSAPI SPNEGO. [CVE-2014-4343 CVE-2014-4344]

Fix buffer overflow vulnerability in LDAP KDB back end.

Fix multiple vulnerabilities in the LDAP KDC back end. [CVE-2014-5354 CVE-2014-5353]

Fix multiple kadmind vulnerabilities, some of which are based in the gssrpc library. [CVE-2014-5352 CVE-2014-9421 CVE-2014-9422 CVE-2014-9423]


Update the affected package.

See Also

Plugin Details

Severity: High

ID: 81534

File Name: freebsd_pkg_dbf9e66cbd5011e4a7ba206a8a720317.nasl

Version: $Revision: 1.1 $

Type: local

Published: 2015/02/26

Modified: 2015/02/26

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:krb5-111, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2015/02/25

Vulnerability Publication Date: 2015/02/25