Vulnerability Bulletins

AIX NAS denial of service vulnerability

   
Affected software IBM
 
1. CVE-2014-5352 Security context handles are not properly maintained, which allows remote authenticated users to cause a denial of service(use-after-free and double free, and daemon crash) or possibly execute arbitrary code via crafted GSSAPI traffic. 2. CVE-2014-5355 A remote attackers can cause a denial of service (NULL pointer dereference) via a zero-byte version string or cause a denial of service(out-of-bounds read) by omitting the character. 3. CVE-2014-9421 Remote authenticated users

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/aix_nas_denial_of_service_vulnerability?lang=en_us