CVE-2005-1174Kerberos 5 vulnerability

10 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
40.9%
top 2.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 18
Latest updateMay 3

Description

MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianmit/krb5< 1.3.6-4+3
NVDmit/kerberos_59 versions+8

Patches

🔴Vulnerability Details

3
GHSA
GHSA-33qx-rqvh-638r: MIT Kerberos 5 (krb5) 12022-05-03
OSV
CVE-2005-1174: MIT Kerberos 5 (krb5) 12005-07-18
CVEList
CVE-2005-1174: MIT Kerberos 5 (krb5) 12005-07-16

📋Vendor Advisories

3
Ubuntu
Kerberos vulnerabilities2005-12-06
Red Hat
security flaw2005-07-12
Debian
CVE-2005-1174: krb5 - MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows rem...2005

💬Community

3
Bugzilla
CVE-2005-1174 security flaw2018-08-16
Bugzilla
CVE-2011-0284 krb5 (krb5kdc): Double-free flaw by handling error messages upon receiving certain AS_REQ's (MITKRB5-SA-2011-003)2011-02-01
Bugzilla
CAN-2004-1009 Multiple mc issues (CAN-2004-1090 CAN-2004-1091 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2005-0763)2005-05-24
CVE-2005-1174 — MIT Kerberos 5 vulnerability | cvebase