{"id":"CVE-2014-5353","details":"The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password policy.","modified":"2026-02-05T13:22:50.019856Z","published":"2014-12-16T23:59:00Z","related":["MGASA-2014-0536","SUSE-SU-2015:1276-1","SUSE-SU-2015:1282-1","openSUSE-SU-2024:10004-1"],"references":[{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2014-0536.html"},{"type":"ADVISORY","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155828.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2015-03/msg00061.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2015-0439.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2015-0794.html"},{"type":"ADVISORY","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2015:009"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/71679"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1031376"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2498-1"},{"type":"ADVISORY","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773226"},{"type":"ADVISORY","url":"https://github.com/krb5/krb5/commit/d1f707024f1d0af6e54a18885322d70fa15ec4d3"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/01/msg00040.html"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-updates/2015-03/msg00061.html"},{"type":"ARTICLE","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773226"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2018/01/msg00040.html"},{"type":"FIX","url":"https://github.com/krb5/krb5/commit/d1f707024f1d0af6e54a18885322d70fa15ec4d3"},{"type":"REPORT","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773226"}],"schema_version":"1.7.3"}