MGASA-2014-0536

Source
https://advisories.mageia.org/MGASA-2014-0536.html
Import Source
https://advisories.mageia.org/MGASA-2014-0536.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0536
Related
Published
2014-12-19T15:06:35Z
Modified
2014-12-19T14:58:22Z
Summary
Updated krb5 packages fix CVE-2014-5353
Details

Updated krb5 packages fix security vulnerability:

In MIT krb5, when kadmind is configured to use LDAP for the KDC database, an authenticated remote attacker can cause a NULL dereference by attempting to use a named ticket policy object as a password policy for a principal. The attacker needs to be authenticated as a user who has the elevated privilege for setting password policy by adding or modifying principals (CVE-2014-5353).

References
Credits

Affected packages

Mageia:4 / krb5

Package

Name
krb5
Purl
pkg:rpm/mageia/krb5?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.11.4-1.3.mga4

Ecosystem specific

{
    "section": "core"
}