Bug 891082 (CVE-2014-4345) - VUL-0: CVE-2014-4345: krb5: buffer overrun in kadmind with LDAP backend (MITKRB5-SA-2014-001)
Summary: VUL-0: CVE-2014-4345: krb5: buffer overrun in kadmind with LDAP backend (MITK...
Status: RESOLVED FIXED
Alias: CVE-2014-4345
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2014-08-19
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/104318/
Whiteboard: maint:released:sle11-sp1:58576 maint:...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-08 15:10 UTC by Alexander Bergmann
Modified: 2014-09-01 15:35 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-08-08 15:10:56 UTC
MIT krb5 Security Advisory 2014-001

Topic: Buffer overrun in kadmind with LDAP backend
CVE: CVE-2014-4345

SUMMARY
=======

In MIT krb5, when kadmind is configured to use LDAP for the KDC
database, an authenticated remote attacker can cause it to perform an
out-of-bounds write (buffer overflow).  This is not a protocol
vulnerability.  Using LDAP for the KDC database is a non-default
configuration for the KDC.

IMPACT
======

Historically, it has been possible to convert an out-of-bounds write
into remote code execution in some cases, though the necessary exploits
must be tailored to the individual application and are usually quite
complicated.  Depending on the allocated length of the array, an
out-of-bounds write may also cause a segmentation fault and/or
application crash.

AFFECTED SOFTWARE
=================

* The kadmind daemon from MIT krb5 releases 1.6 to 1.12.2, when
  configured to use the LDAP backend for the KDB, is vulnerable.
  Releases of MIT krb5 prior to 1.6 did not provide the ability to use
  LDAP for the KDB backend.

See full details and patches at the mit.edu website.

References:
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2014-001.txt
https://bugzilla.redhat.com/show_bug.cgi?id=1128157
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-4345
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4345
Comment 1 Swamp Workflow Management 2014-08-08 22:00:13 UTC
bugbot adjusting priority
Comment 4 Bernhard Wiedemann 2014-08-11 12:00:38 UTC
This is an autogenerated message for OBS integration:
This bug (891082) was mentioned in
https://build.opensuse.org/request/show/244208 13.1+12.3 / krb5+krb5-mini+krb5-doc
Comment 5 Swamp Workflow Management 2014-08-12 08:47:48 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2014-08-19.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/58552
Comment 6 SMASH SMASH 2014-08-12 08:50:13 UTC
Affected packages:

SLE-10-SP3-TERADATA: krb5
SLE-11-SP1: krb5
SLE-11-SP3: krb5
Comment 7 Swamp Workflow Management 2014-08-15 23:04:30 UTC
SUSE-SU-2014:1028-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 891082
CVE References: CVE-2014-4345
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    krb5-1.6.3-133.49.62.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    krb5-1.6.3-133.49.62.1, krb5-doc-1.6.3-133.49.62.1, krb5-plugins-1.6.3-133.49.62.1
SUSE Linux Enterprise Server 11 SP3 (src):    krb5-1.6.3-133.49.62.1, krb5-doc-1.6.3-133.49.62.1, krb5-plugins-1.6.3-133.49.62.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    krb5-1.6.3-133.49.62.1
Comment 8 Swamp Workflow Management 2014-08-20 17:06:53 UTC
openSUSE-SU-2014:1043-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 891082
CVE References: CVE-2014-4345
Sources used:
openSUSE 13.1 (src):    krb5-1.11.3-3.12.1, krb5-mini-1.11.3-3.12.1
openSUSE 12.3 (src):    krb5-1.10.2-10.30.1, krb5-doc-1.10.2-10.30.2, krb5-mini-1.10.2-10.30.1
Comment 9 Marcus Meissner 2014-09-01 15:35:06 UTC
was released