CVE Database
/

CVE-2002-1235

Back to search

CVE-2002-1235

Published: Oct 25, 2002

Modified: Aug 8, 2024

PUBLISHED

Description

The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDKSA-2002:073
vendor-advisory
x_refsource_MANDRAKE
20021027 Re: Buffer overflow in kadmind4
mailing-list
x_refsource_BUGTRAQ
DSA-185
vendor-advisory
x_refsource_DEBIAN
20021028 GLSA: krb5
mailing-list
x_refsource_BUGTRAQ
DSA-183
vendor-advisory
x_refsource_DEBIAN
kerberos-kadmind-bo(10430)
vdb-entry
x_refsource_XF
CLA-2002:534
vendor-advisory
x_refsource_CONECTIVA
CA-2002-29
third-party-advisory
x_refsource_CERT
DSA-184
vendor-advisory
x_refsource_DEBIAN
VU#875073
third-party-advisory
x_refsource_CERT-VN
RHSA-2002:242
vendor-advisory
x_refsource_REDHAT
6024
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now