CVE-2002-1225
published 2002-10-28CVE-2002-1225: Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.
PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.55%
90.6th percentile
Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heimdal | < heimdal 0.4e-21 (bookworm) | heimdal 0.4e-21 (bookworm) |
| heimdal_project | heimdal | >= 0 < 0.4e-21 | 0.4e-21 |
| heimdal_project | heimdal | >= 0 < 0.4e-21 | 0.4e-21 |
| heimdal_project | heimdal | >= 0 < 0.4e-21 | 0.4e-21 |
| heimdal_project | heimdal | >= 0 < 0.4e-21 | 0.4e-21 |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vvvj-29m3-wc9p: Unknown vulnerabilities in Heimdal before 0
ghsa_unreviewed·2022-04-30·CVSS 10.0
CVE-2002-1226 [CRITICAL] GHSA-vvvj-29m3-wc9p: Unknown vulnerabilities in Heimdal before 0
Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225).
GHSA
GHSA-7gh5-g6w7-v7hq: Multiple buffer overflows in Heimdal before 0
ghsa_unreviewed·2022-04-30
CVE-2002-1225 [HIGH] GHSA-7gh5-g6w7-v7hq: Multiple buffer overflows in Heimdal before 0
Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.
OSV
CVE-2002-1225: Multiple buffer overflows in Heimdal before 0
osv·2002-10-28·CVSS 10.0
CVE-2002-1225 [CRITICAL] CVE-2002-1225: Multiple buffer overflows in Heimdal before 0
Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.
OSV
CVE-2002-1226: Unknown vulnerabilities in Heimdal before 0
osv·2002-10-28·CVSS 10.0
CVE-2002-1226 [CRITICAL] CVE-2002-1226: Unknown vulnerabilities in Heimdal before 0
Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225).
Debian
CVE-2002-1225: heimdal - Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmin...
vendor_debian·2002·CVSS 10.0
CVE-2002-1225 [CRITICAL] CVE-2002-1225: heimdal - Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmin...
Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.
Scope: local
bookworm: resolved (fixed in 0.4e-21)
bullseye: resolved (fixed in 0.4e-21)
forky: resolved (fixed in 0.4e-21)
sid: resolved (fixed in 0.4e-21)
trixie: resolved (fixed in 0.4e-21)
Debian
CVE-2002-1226: heimdal - Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in t...
vendor_debian·2002·CVSS 10.0
CVE-2002-1226 [CRITICAL] CVE-2002-1226: heimdal - Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in t...
Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225).
Scope: local
bookworm: resolved (fixed in 0.4e-21)
bullseye: resolved (fixed in 0.4e-21)
forky: resolved (fixed in 0.4e-21)
sid: resolved (fixed in 0.4e-21)
trixie: resolved (fixed in 0.4e-21)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=103341355708817&w=2http://marc.info/?l=bugtraq&m=103462479621246&w=2http://www.debian.org/security/2002/dsa-178http://www.iss.net/security_center/static/10116.phphttp://www.securityfocus.com/bid/5729http://marc.info/?l=bugtraq&m=103341355708817&w=2http://marc.info/?l=bugtraq&m=103462479621246&w=2http://www.debian.org/security/2002/dsa-178http://www.iss.net/security_center/static/10116.phphttp://www.securityfocus.com/bid/5729
2002-10-28
Published