CVE-2002-0600Kerberos vulnerability

3 documents3 sources
Severity
7.5HIGHNVD
EPSS
1.7%
top 17.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 18
Latest updateApr 30

Description

Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDkth/kth_kerberos4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-v9mh-h583-pwc5: Heap overflow in the KTH Kerberos 4 FTP client 4-12022-04-30
CVEList
CVE-2002-0600: Heap overflow in the KTH Kerberos 4 FTP client 4-12002-06-11
CVE-2002-0600 — KTH Kerberos vulnerability | cvebase