---
title: "CVE-2014-9278\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-9278?format=md
keywords: index, follow
---

# CVE-2014-9278

Publication date 6 December 2014

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and
when running in a Kerberos environment, allows remote authenticated users
to log in as another user when they are listed in the .k5users file of that
user, which might bypass intended authentication requirements that would
force a local login.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-9278?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openssh | 14.10 utopic | Not affected |
| 14.04 LTS trusty | Not affected |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

vulnerable patch not included in Debian/Ubuntu

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9278)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-9278)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-9278)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-9278)

### Other references

* <https://bugzilla.redhat.com/show_bug.cgi?id=1169843>
* <https://www.cve.org/CVERecord?id=CVE-2014-9278>
