Vulnerability Bulletins |
AIX NAS denial of service vulnerability |
|
| Affected software | IBM |
|
1. CVE-2014-5352 Security context handles are not properly maintained, which allows remote authenticated users to cause a denial of service(use-after-free and double free, and daemon crash) or possibly execute arbitrary code via crafted GSSAPI traffic. 2. CVE-2014-5355 A remote attackers can cause a denial of service (NULL pointer dereference) via a zero-byte version string or cause a denial of service(out-of-bounds read) by omitting the character. 3. CVE-2014-9421 Remote authenticated users More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/aix_nas_denial_of_service_vulnerability?lang=en_us |
|






