CVE Database
/

CVE-2004-1189

Back to search

CVE-2004-1189

Published: Dec 31, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

CLA-2005:917
vendor-advisory
x_refsource_CONECTIVA
oval:org.mitre.oval:def:11911
vdb-entry
signature
x_refsource_OVAL
kerberos-libkadm5srv-bo(18621)
vdb-entry
x_refsource_XF
RHSA-2005:012
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2005-08-15
vendor-advisory
x_refsource_APPLE
APPLE-SA-2005-08-17
vendor-advisory
x_refsource_APPLE
2004-0069
vendor-advisory
x_refsource_TRUSTIX
RHSA-2005:045
vendor-advisory
x_refsource_REDHAT
MDKSA-2004:156
vendor-advisory
x_refsource_MANDRAKE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now