CVE Vulnerabilities

CVE-2002-1235

Published: Nov 04, 2002 | Modified: Jan 21, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

Affected Software

Name Vendor Start Version End Version
Kth_kerberos_4 Kth * 1.2.1 (excluding)
Kth_kerberos_5 Kth * 0.5.1 (excluding)
Kerberos_5 Mit 1.0 (including) 1.2.6 (including)

References