CVE-2014-5354

low
Published 2014-12-16 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by creating a database entry for a keyless principal, as demonstrated by a kadmin "add_principal -nokey" or "purgekeys -all" command.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-5354

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.12.1+dfsg-16
debian debianbullseyefixed1.12.1+dfsg-16
debian debianforkyfixed1.12.1+dfsg-16
debian debiansidfixed1.12.1+dfsg-16
debian debiantrixiefixed1.12.1+dfsg-16

Application impact

VendorProductVersionsFixed
mitkerberos5_1.13
mitkerberos_51.12
mitkerberos_51.12.1
mitkerberos_51.12.2

References

Verify integrity in audit chain (admin only). AS-IS.