Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 16 Dec 2014 14:40:55 +1100
From: Murray McAllister <mmcallis@...hat.com>
To: oss-security@...ts.openwall.com
Subject: krb5: kadmin NULL pointer dereference issues, CVE-2014-5353 and CVE-2014-5354

Good morning,

If anyone missed it, there are two NULL pointer dereference issues when 
kadmind is used with an LDAP back end for the KDC database. Both require 
authentication.

CVE-2014-5353
https://github.com/krb5/krb5/commit/d1f707024f1d0af6e54a18885322d70fa15ec4d3

CVE-2014-5354
https://github.com/krb5/krb5/commit/04038bf3633c4b909b5ded3072dc88c8c419bf16

References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773226
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773228

Cheers,

--
Murray McAllister / Red Hat Product Security

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.