MIT Kerberos 5 CVE-2014-4344 NULL Pointer Dereference Remote Denial of Service Vulnerability
BID:69160
Info
MIT Kerberos 5 CVE-2014-4344 NULL Pointer Dereference Remote Denial of Service Vulnerability
| Bugtraq ID: | 69160 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-4344 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 2014 12:00AM |
| Updated: | May 07 2015 05:10PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS Ubuntu Ubuntu Linux 10.04 LTS Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Enterprise Linux 7 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 MIT Kerberos 5 1.12.1 MIT Kerberos 5 1.11.1 MIT Kerberos 5 1.10.6 MIT Kerberos 5 1.10.4 MIT Kerberos 5 1.10.3 MIT Kerberos 5 1.9.5 MIT Kerberos 5 1.8.4 MIT Kerberos 5 1.8.3 MIT Kerberos 5 1.8.2 MIT Kerberos 5 1.8.1 MIT Kerberos 5 1.7.2 MIT Kerberos 5 1.7.1 MIT Kerberos 5 1.6.4 MIT Kerberos 5 1.6.3 MIT Kerberos 5 1.6.2 MIT Kerberos 5 1.6.1 MIT Kerberos 5 1.6 MIT Kerberos 5 1.5.5 MIT Kerberos 5 1.5.4 MIT Kerberos 5 1.5.3 MIT Kerberos 5 1.5.2 MIT Kerberos 5 1.5.1 MIT Kerberos 5 1.5 MIT Kerberos 5 1.9 MIT Kerberos 5 1.8 MIT Kerberos 5 1.7 MIT Kerberos 5 1.5 MIT Kerberos 5 1.12 MIT Kerberos 5 1.11.4 MIT Kerberos 5 1.11.3 MIT Kerberos 5 1.11.2 MIT Kerberos 5 1.10.7 MIT Kerberos 5 1.10.2 MIT Kerberos 5 1.10.1 MIT Kerberos 5 1.10 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 IBM Vios 2.2.3 IBM Vios 2.2.1 4 IBM Vios 2.2 IBM Vios 2.2.3.4 IBM Vios 2.2.3.3 IBM Vios 2.2.3.2 IBM Vios 2.2.3.0 IBM Vios 2.2.2.5 IBM Vios 2.2.2.4 IBM Vios 2.2.2.0 IBM Vios 2.2.1.9 IBM Vios 2.2.1.8 IBM Vios 2.2.1.3 IBM Vios 2.2.1.1 IBM Vios 2.2.1.0 IBM Vios 2.2.0.13 IBM Vios 2.2.0.12 IBM Vios 2.2.0.11 IBM Vios 2.2.0.10 IBM AIX 7.1 IBM AIX 6.1 IBM AIX 5.3 F5 BIG-IP Edge Gateway 11.3 F5 BIG-IP Edge Gateway 11.2.1 HF3 F5 BIG-IP Edge Gateway 11.2.1 F5 BIG-IP Edge Gateway 11.2 HF3 F5 BIG-IP Edge Gateway 11.2 F5 BIG-IP Edge Gateway 11.1 F5 BIG-IP Edge Gateway 11.0 F5 BIG-IP Edge Gateway 10.2.4 F5 BIG-IP Edge Gateway 10.2.2 F5 BIG-IP Edge Gateway 10.2.1 F5 BIG-IP Edge Gateway 10.1 F5 BIG-IP Edge Gateway 11.2.1 HF5 F5 BIG-IP Edge Gateway 11.2.1 HF2 F5 BIG-IP Edge Gateway 11.2.0 HF5 F5 BIG-IP Edge Gateway 11.1.0 HF7 F5 BIG-IP Edge Gateway 10.2.1 HF1 F5 BIG-IP APM 11.5.1 F5 BIG-IP APM 11.2 F5 BIG-IP APM 11.0 F5 BIG-IP APM 10.2.4 F5 BIG-IP APM 10.2.2 F5 BIG-IP APM 11.5.0 F5 BIG-IP APM 11.4.1 F5 BIG-IP APM 11.4.0 F5 BIG-IP APM 11.3.0 HF4 F5 BIG-IP APM 11.3.0 F5 BIG-IP APM 11.2.1 HF5 F5 BIG-IP APM 11.2.1 HF3 F5 BIG-IP APM 11.2.1 HF2 F5 BIG-IP APM 11.2.1 HF1 F5 BIG-IP APM 11.2.1 F5 BIG-IP APM 11.2.0 HF5 F5 BIG-IP APM 11.2.0 HF3 F5 BIG-IP APM 11.2.0 HF2 F5 BIG-IP APM 11.1.0 HF7 F5 BIG-IP APM 11.1.0 F5 BIG-IP APM 10.2.1 HF1 F5 BIG-IP APM 10.2.1 F5 BIG-IP APM 10.1 F5 ARX 6.4 F5 ARX 6.3 F5 ARX 6.2 F5 ARX 6.1.1 F5 ARX 6.1 F5 ARX 6.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya Proactive Contact 5.1 Avaya Proactive Contact 5.0 Avaya one-X Client Enablement Services 6.2 Avaya one-X Client Enablement Services 6.1 SP2 Avaya one-X Client Enablement Services 6.1 SP1 Avaya one-X Client Enablement Services 6.1 Avaya Message Networking 6.2.0 Avaya Meeting Exchange 6.2 Avaya Meeting Exchange 6.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Server Edition 9.0 Avaya IP Office Server Edition 8.1 Avaya IP Office Application Server 9.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Communication Server 1000M Signaling Server 7.6 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.6 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.6 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.6 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya CMS r17 Avaya Aura System Platform 6.2.2 Avaya Aura System Platform 6.2.1 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.3 Avaya Aura System Platform 6.2.1.0.9 Avaya Aura System Platform 6.2 SP1 Avaya Aura System Platform 6.2 Avaya Aura System Platform 6.0.3.9.3 Avaya Aura System Platform 6.0.3.8.3 Avaya Aura System Platform 6.0.3.0.3 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.3.6 Avaya Aura System Manager 6.3.4 Avaya Aura System Manager 6.3.2 Avaya Aura System Manager 6.3.1 Avaya Aura System Manager 6.3.3 Avaya Aura System Manager 6.3 Avaya Aura System Manager 6.2.4 Avaya Aura System Manager 6.2.3 Avaya Aura System Manager 6.2 SP3 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.7 Avaya Aura System Manager 6.1.5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura System Manager 5.0 Avaya Aura Session Manager 6.3.1 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.5 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.0.1 Avaya Aura Session Manager 6.3.3 Avaya Aura Session Manager 6.3 Avaya Aura Session Manager 6.2.4 Avaya Aura Session Manager 6.2.3 Avaya Aura Session Manager 6.2.2 Avaya Aura Session Manager 6.2 SP1 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1.7 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0.2 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2.4 Avaya Aura Session Manager 5.2.1 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 5.0 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Messaging 6.1.1 Avaya Aura Messaging 6.3 Avaya Aura Messaging 6.2 SP4 Avaya Aura Messaging 6.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 7.0 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing Standard Edition 6.0 Avaya Aura Conferencing 8.0 Avaya Aura Conferencing 7.2 Avaya Aura Conferencing 7.0 Avaya Aura Communication Manager Utility Services 6.3 Avaya Aura Communication Manager Utility Services 6.2.5.0.15 Avaya Aura Communication Manager Utility Services 6.2.4.0.15 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 SP 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.3 Avaya Aura Communication Manager 6.2 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Collaboration Environment 3.0 Avaya Aura Collaboration Environment 2.0 Avaya Aura Application Server 5300 SIP Core 3.0 PB5 Avaya Aura Application Server 5300 SIP Core 3.0 PB3 Avaya Aura Application Server 5300 SIP Core 3.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 PB28 Avaya Aura Application Server 5300 SIP Core 2.0 PB26 Avaya Aura Application Server 5300 SIP Core 2.0 PB25 Avaya Aura Application Server 5300 SIP Core 2.0 PB23 Avaya Aura Application Server 5300 SIP Core 2.0 PB19 Avaya Aura Application Server 5300 SIP Core 2.0 PB16 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.3 Avaya Aura Application Enablement Services 6.2 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 6.0 Avaya Aura Application Enablement Services 5.2.4 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Avaya Aura Application Enablement Services 5.0 |
| Not Vulnerable: |
MIT Kerberos 5 1.12.2 |
Discussion
MIT Kerberos 5 CVE-2014-4344 NULL Pointer Dereference Remote Denial of Service Vulnerability
MIT Kerberos 5 is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause a program to crash, resulting in denial-of-service conditions.
Versions prior to Kerberos 5 1.12.2 are vulnerable.
MIT Kerberos 5 is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause a program to crash, resulting in denial-of-service conditions.
Versions prior to Kerberos 5 1.12.2 are vulnerable.
Exploit / POC
MIT Kerberos 5 CVE-2014-4344 NULL Pointer Dereference Remote Denial of Service Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
MIT Kerberos 5 CVE-2014-4344 NULL Pointer Dereference Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
MIT Kerberos 5 CVE-2014-4344 NULL Pointer Dereference Remote Denial of Service Vulnerability
References:
References:
- Kerberos Homepage (MIT)