MIT Kerberos 5 'kadmind' Daemon CVE-2014-9421 Remote Code Execution Vulnerability
BID:72496
Info
MIT Kerberos 5 'kadmind' Daemon CVE-2014-9421 Remote Code Execution Vulnerability
| Bugtraq ID: | 72496 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-9421 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2015 12:00AM |
| Updated: | Nov 03 2015 07:50PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.10 Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server EUS 6.6.z Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop 6 Oracle Enterprise Linux 7 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 MIT Kerberos 5 1.12.2 MIT Kerberos 5 1.12.1 MIT Kerberos 5 1.11.6 MIT Kerberos 5 1.11.1 MIT Kerberos 5 1.13 MIT Kerberos 5 1.12 MIT Kerberos 5 1.11.4 MIT Kerberos 5 1.11.3 MIT Kerberos 5 1.11.2 IBM SmartCloud Provisioning 2.1 IBM Security Network Protection 5.3 IBM Security Network Protection 5.2.0 IBM Security Network Intrusion Prevention System GX7800 4.6.2 IBM Security Network Intrusion Prevention System GX7800 4.6.1 IBM Security Network Intrusion Prevention System GX7800 4.6 IBM Security Network Intrusion Prevention System GX7800 4.5 IBM Security Network Intrusion Prevention System GX7800 4.4 IBM Security Network Intrusion Prevention System GX7800 4.3 IBM Security Network Intrusion Prevention System GX7412-10 4.6.2 IBM Security Network Intrusion Prevention System GX7412-10 4.6.1 IBM Security Network Intrusion Prevention System GX7412-10 4.6 IBM Security Network Intrusion Prevention System GX7412-10 4.5 IBM Security Network Intrusion Prevention System GX7412-10 4.4 IBM Security Network Intrusion Prevention System GX7412-10 4.3 IBM Security Network Intrusion Prevention System GX7412-05 4.6.2 IBM Security Network Intrusion Prevention System GX7412-05 4.6.1 IBM Security Network Intrusion Prevention System GX7412-05 4.6 IBM Security Network Intrusion Prevention System GX7412-05 4.5 IBM Security Network Intrusion Prevention System GX7412-05 4.4 IBM Security Network Intrusion Prevention System GX7412-05 4.3 IBM Security Network Intrusion Prevention System GX7412 4.6.2 IBM Security Network Intrusion Prevention System GX7412 4.6.1 IBM Security Network Intrusion Prevention System GX7412 4.6 IBM Security Network Intrusion Prevention System GX7412 4.5 IBM Security Network Intrusion Prevention System GX7412 4.4 IBM Security Network Intrusion Prevention System GX7412 4.3 IBM Security Network Intrusion Prevention System GX6116 4.6.2 IBM Security Network Intrusion Prevention System GX6116 4.6.1 IBM Security Network Intrusion Prevention System GX6116 4.6 IBM Security Network Intrusion Prevention System GX6116 4.5 IBM Security Network Intrusion Prevention System GX6116 4.4 IBM Security Network Intrusion Prevention System GX6116 4.3 IBM Security Network Intrusion Prevention System GX5208-v2 4.6.2 IBM Security Network Intrusion Prevention System GX5208-v2 4.6.1 IBM Security Network Intrusion Prevention System GX5208-v2 4.6 IBM Security Network Intrusion Prevention System GX5208-v2 4.5 IBM Security Network Intrusion Prevention System GX5208-v2 4.4 IBM Security Network Intrusion Prevention System GX5208-v2 4.3 IBM Security Network Intrusion Prevention System GX5208 4.6.2 IBM Security Network Intrusion Prevention System GX5208 4.6.1 IBM Security Network Intrusion Prevention System GX5208 4.6 IBM Security Network Intrusion Prevention System GX5208 4.5 IBM Security Network Intrusion Prevention System GX5208 4.4 IBM Security Network Intrusion Prevention System GX5208 4.3 IBM Security Network Intrusion Prevention System GX5108-v2 4.6.2 IBM Security Network Intrusion Prevention System GX5108-v2 4.6.1 IBM Security Network Intrusion Prevention System GX5108-v2 4.6 IBM Security Network Intrusion Prevention System GX5108-v2 4.5 IBM Security Network Intrusion Prevention System GX5108-v2 4.4 IBM Security Network Intrusion Prevention System GX5108-v2 4.3 IBM Security Network Intrusion Prevention System GX5108 4.6.2 IBM Security Network Intrusion Prevention System GX5108 4.6.1 IBM Security Network Intrusion Prevention System GX5108 4.6 IBM Security Network Intrusion Prevention System GX5108 4.5 IBM Security Network Intrusion Prevention System GX5108 4.4 IBM Security Network Intrusion Prevention System GX5108 4.3 IBM Security Network Intrusion Prevention System GX5008-v2 4.6.2 IBM Security Network Intrusion Prevention System GX5008-v2 4.6.1 IBM Security Network Intrusion Prevention System GX5008-v2 4.6 IBM Security Network Intrusion Prevention System GX5008-v2 4.5 IBM Security Network Intrusion Prevention System GX5008-v2 4.4 IBM Security Network Intrusion Prevention System GX5008-v2 4.3 IBM Security Network Intrusion Prevention System GX5008 4.6.2 IBM Security Network Intrusion Prevention System GX5008 4.6.1 IBM Security Network Intrusion Prevention System GX5008 4.6 IBM Security Network Intrusion Prevention System GX5008 4.5 IBM Security Network Intrusion Prevention System GX5008 4.4 IBM Security Network Intrusion Prevention System GX5008 4.3 IBM Security Network Intrusion Prevention System GX4004-v2 4.6.2 IBM Security Network Intrusion Prevention System GX4004-v2 4.6.1 IBM Security Network Intrusion Prevention System GX4004-v2 4.6 IBM Security Network Intrusion Prevention System GX4004-v2 4.5 IBM Security Network Intrusion Prevention System GX4004-v2 4.4 IBM Security Network Intrusion Prevention System GX4004-v2 4.3 IBM Security Network Intrusion Prevention System GX4004 4.6.2 IBM Security Network Intrusion Prevention System GX4004 4.6.1 IBM Security Network Intrusion Prevention System GX4004 4.6 IBM Security Network Intrusion Prevention System GX4004 4.5 IBM Security Network Intrusion Prevention System GX4004 4.4 IBM Security Network Intrusion Prevention System GX4004 4.3 IBM Security Network Intrusion Prevention System GX4002 4.6.2 IBM Security Network Intrusion Prevention System GX4002 4.6.1 IBM Security Network Intrusion Prevention System GX4002 4.6 IBM Security Network Intrusion Prevention System GX4002 4.5 IBM Security Network Intrusion Prevention System GX4002 4.4 IBM Security Network Intrusion Prevention System GX4002 4.3 IBM Security Network Intrusion Prevention System GX3002 4.6.2 IBM Security Network Intrusion Prevention System GX3002 4.6.1 IBM Security Network Intrusion Prevention System GX3002 4.6 IBM Security Network Intrusion Prevention System GX3002 4.5 IBM Security Network Intrusion Prevention System GX3002 4.4 IBM Security Network Intrusion Prevention System GX3002 4.3 IBM Security Network Intrusion Prevention System GV200 4.6.2 IBM Security Network Intrusion Prevention System GV200 4.6.1 IBM Security Network Intrusion Prevention System GV200 4.6 IBM Security Network Intrusion Prevention System GV200 4.5 IBM Security Network Intrusion Prevention System GV200 4.4 IBM Security Network Intrusion Prevention System GV200 4.3 IBM Security Network Intrusion Prevention System GV1000 4.6.2 IBM Security Network Intrusion Prevention System GV1000 4.6.1 IBM Security Network Intrusion Prevention System GV1000 4.6 IBM Security Network Intrusion Prevention System GV1000 4.5 IBM Security Network Intrusion Prevention System GV1000 4.4 IBM Security Network Intrusion Prevention System GV1000 4.3 IBM PowerKVM 2.1 IBM Power HMC 8.8.2.0 IBM Power HMC 8.8.1.0 CentOS CentOS 6 Avaya one-X Client Enablement Services 6.2 SP2 Avaya one-X Client Enablement Services 6.2 Avaya IP Office Server Edition 9.0 Avaya IP Office Server Edition 8.1 Avaya IP Office Application Server 9.0 SP 2 Avaya IP Office Application Server 9.0 SP 1 Avaya IP Office Application Server 9.0 Avaya CMS R17ac.h Avaya CMS R17ac.g Avaya CMS R17 R4 Avaya CMS R17 R3 Avaya CMS r17 Avaya Aura Session Manager 6.3.1 Avaya Aura Session Manager 6.3.3 Avaya Aura Session Manager 6.3 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 7.0 Avaya Aura Experience Portal 6.0 SP2 Avaya Aura Experience Portal 6.0 SP1 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 8.0 SP2 Avaya Aura Conferencing 8.0 SP1 Avaya Aura Conferencing 8.0 Avaya Aura Collaboration Environment 3.0 Avaya Aura Collaboration Environment 2.0 |
| Not Vulnerable: | |
Discussion
MIT Kerberos 5 'kadmind' Daemon CVE-2014-9421 Remote Code Execution Vulnerability
MIT Kerberos 5 is prone to a remote code-execution vulnerability in 'kadmind'.
An attacker may exploit this issue to execute arbitrary code in the context of the affected application. Failed attempts will cause the affected application to crash, denying service to legitimate users.
MIT Kerberos 5 is prone to a remote code-execution vulnerability in 'kadmind'.
An attacker may exploit this issue to execute arbitrary code in the context of the affected application. Failed attempts will cause the affected application to crash, denying service to legitimate users.
Solution / Fix
MIT Kerberos 5 'kadmind' Daemon CVE-2014-9421 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
MIT Kerberos 5 'kadmind' Daemon CVE-2014-9421 Remote Code Execution Vulnerability
References:
References:
- Kerberos Homepage (MIT)