CVE-2014-9423
Publication date 3 February 2015
Last updated 24 July 2024
Ubuntu priority
The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.
Status
Package | Ubuntu Release | Status |
---|---|---|
krb5 | ||
14.04 LTS trusty |
Fixed 1.12+dfsg-2ubuntu5.1
|
|
Patch details
Package | Patch details |
---|---|
krb5 |
|
References
Related Ubuntu Security Notices (USN)
- USN-2498-1
- Kerberos vulnerabilities
- 10 February 2015