CVE-2002-1235Kerberos 4 vulnerability

12 documents9 sources
Severity
10.0CRITICALNVD
EPSS
32.9%
top 3.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateMay 3

Description

The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages5 packages

NVDkth/kth_kerberos_4< 1.2.1
NVDkth/kth_kerberos_5< 0.5.1
NVDmit/kerberos_51.01.2.6
Debianmit/krb5< 1.2.6-2+3
Debianheimdal_project/heimdal< 0.4e-22+3

Also affects: Debian Linux 3.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-r4jv-xp6w-68qp: The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-12022-05-03
OSV
CVE-2002-1235: The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-12002-11-04
CVEList
CVE-2002-1235: The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-12002-10-25
VulnCheck
Kerberos v4compatibility Administration Daemon (kadmind4) Remote Code Execution2002

🔍Detection Rules

4
Suricata
GPL EXPLOIT kadmind buffer overflow attempt2010-09-23
Suricata
GPL EXPLOIT kadmind buffer overflow attempt2010-09-23
Suricata
GPL EXPLOIT kadmind buffer overflow attempt2010-09-23
Suricata
GPL EXPLOIT kadmind buffer overflow attempt2010-09-23

📋Vendor Advisories

2
Red Hat
security flaw2002-10-23
Debian
CVE-2002-1235: heimdal - The kadm_ser_in function in (1) the Kerberos v4compatibility administration daem...2002

💬Community

1
Bugzilla
CVE-2002-1235 security flaw2018-08-16
CVE-2002-1235 — KTH Kerberos 4 vulnerability | cvebase