New Search

RHSA-2014:1255: krb5 security update (Moderate)

oval:org.mitre.oval:def:26718

Kerberos is an authentication system which allows clients and services to authenticate to each other with the help of a trusted third party a Kerberos Key Distribution Center (KDC). A buffer overflow was found in the KADM5 administration server (kadmind) when it was used with an LDAP back end for the KDC database. A remote authenticated attacker could potentially use this flaw to execute arbitrary code on the system running kadmind. (CVE-2014-4345) All krb5 users are advised to upgrade to these updated packages which contain a backported patch to correct this issue. After installing the updated packages the krb5kdc and kadmind daemons will be restarted automatically.

Family:
unix
Status:
ACCEPTED
Platform(s):
  • CentOS Linux 5
  • Red Hat Enterprise Linux 5
Class:
patch
Reference(s):
  • RHSA-2014:1255-00
  • CVE-2014-4345
  • CESA-2014:1255
Product(s):
  • krb5