← Back

CVE-2014-5354

nvd nist
Published: Dec 16, 2014Modified: May 6, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:N/A:P
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by creating a database entry for a keyless principal, as demonstrated by a kadmin "add_principal -nokey" or "purgekeys -all" command.

Affected (4)

Products: Mit: Kerberos, Kerberos 5
2 products
Kerberos
Kerberos 5
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 5_1.13
Mit
Version 1.12.1
Version 1.12.2
Version 1.12

References (10)

Timeline

No history available yet.