USN-4314-1: pam-krb5 vulnerability
Published Mar 31, 2020
·Updated
Russ Allbery discovered that pam-krb5 incorrectly handled some responses. An attacker could possibly use this issue to execute arbitrary code.
Affected Software
10 affected componentsFixes available
All of the following
ubuntu/libpam-krb5<4.8-2ubuntu0.1
4.8-2ubuntu0.1
Ubuntu Ubuntu=19.10
All of the following
ubuntu/libpam-krb5<4.8-1ubuntu0.1
4.8-1ubuntu0.1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libpam-krb5<4.7-2ubuntu0.1
4.7-2ubuntu0.1
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libpam-krb5<4.6-2ubuntu0.1~esm1
4.6-2ubuntu0.1~esm1
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libpam-krb5<4.5-3ubuntu0.1
4.5-3ubuntu0.1
Ubuntu Ubuntu=12.04
Event History
Mar 31, 2020
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-4314-1?
The severity of USN-4314-1 is critical due to the potential for arbitrary code execution by an attacker.
2
How do I fix USN-4314-1?
To fix USN-4314-1, update the libpam-krb5 package to the latest version available for your Ubuntu release.
3
Which Ubuntu versions are affected by USN-4314-1?
USN-4314-1 affects Ubuntu versions 19.10, 18.04, 16.04, 14.04, and 12.04 with specific libpam-krb5 versions.
4
Is USN-4314-1 a remote code execution vulnerability?
Yes, USN-4314-1 is a remote code execution vulnerability that allows attackers to execute arbitrary code remotely.
5
Who discovered the vulnerability in USN-4314-1?
The vulnerability in USN-4314-1 was discovered by Russ Allbery.