CVE-2014-5353: Canonical Ubuntu Linux

Low severity, CVSS 3.5. EPSS: 5% chance of exploitation in the next 30 days.

The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password policy.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
  • Debian Debian Linux: version 7.0 only
  • Fedoraproject Fedora: version 22 only
  • Mit Kerberos 5: before 1.13.1 (fixed in 1.13.1)
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Oracle Solaris: version 10 only; version 11.2 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.6 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.6 only; version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server Tus: version 6.6 only; version 7.3 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2014-12-16. Last modified 2026-06-17.