Advisories ยป MGASA-2015-0119

Updated krb5 package fixes security vulnerability

Publication date: 27 Mar 2015
Modification date: 09 Jul 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-5355

Description

MIT Kerberos 5 through 1.13.1 incorrectly expects that a krb5_read_message
data field is represented as a string ending with a '\0' character, which
allows remote attackers to cause a denial of service (NULL pointer
dereference) via a zero-byte version string or cause a denial of service
(out-of-bounds read) by omitting the '\0' character, related to
appl/user_user/server.c and lib/krb5/krb/recvauth.c (CVE-2014-5355).
                

References

SRPMS

4/core