CVE-2000-0548Classic Buffer Overflow in Kerberos

Severity
5.0MEDIUMNVD
EPSS
3.4%
top 12.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 9
Latest updateApr 30

Description

Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDmit/kerberos< 4.0+1
NVDmit/kerberos_51.01.0.7+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gpr4-gfq8-c66q: Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function2022-04-30
CVEList
CVE-2000-0548: Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function2000-10-13

💥Exploits & PoCs

1
Exploit-DB
Solaris 2.6/7.0 - DTMail Mail Environment Variable Buffer Overflow2001-07-24

📋Vendor Advisories

1
Red Hat
security flaw2000-06-09

💬Community

1
Bugzilla
CVE-2000-0548 security flaw2018-08-16
CVE-2000-0548 — Classic Buffer Overflow in MIT Kerberos | cvebase