CVE-2014-9423
Summary
| CVE | CVE-2014-9423 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-02-19 11:59:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mit | Kerberos 5 | 1.11 | All | All | All |
| Application | Mit | Kerberos 5 | 1.11.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.11.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.11.3 | All | All | All |
| Application | Mit | Kerberos 5 | 1.11.4 | All | All | All |
| Application | Mit | Kerberos 5 | 1.11.5 | All | All | All |
| Application | Mit | Kerberos 5 | 1.12 | All | All | All |
| Application | Mit | Kerberos 5 | 1.12.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.12.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.13 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| web.mit.edu/kerberos/advisories/MITKRB5-SA-2015-001.txt | af854a3a-2127-422b-91ae-364da2661108 | web.mit.edu | Vendor Advisory |
| [SECURITY] Fedora 21 Update: krb5-1.12.2-14.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [security-announce] SUSE-SU-2015:0257-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [SECURITY] Fedora 20 Update: krb5-1.11.5-18.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| MIT Kerberos 5 CVE-2014-9423 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-2498-1: Kerberos vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Support / Security / Advisories / / MDVSA-2015:069 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| openSUSE-SU-2015:0255-1: moderate: Security update for krb5 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] SUSE-SU-2015:0290-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Fix gssrpc data leakage [CVE-2014-9423] · krb5/krb5@5bb8a6b · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Debian -- Security Information -- DSA-3153-1 krb5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| web.mit.edu/kerberos/advisories/2015-001-patch-r113.txt | af854a3a-2127-422b-91ae-364da2661108 | web.mit.edu | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.