CVE-2014-5353: Canonical Ubuntu Linux
Low severity, CVSS 3.5. EPSS: 5% chance of exploitation in the next 30 days.
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password policy.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
- Debian Debian Linux: version 7.0 only
- Fedoraproject Fedora: version 22 only
- Mit Kerberos 5: before 1.13.1 (fixed in 1.13.1)
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Oracle Solaris: version 10 only; version 11.2 only
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Eus: version 6.6 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 6.6 only; version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Tus: version 6.6 only; version 7.3 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 6.0 only
Published 2014-12-16. Last modified 2026-06-17.