CVE-2005-1689
published 2005-07-18CVE-2005-1689: Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via…
PriorityP339critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
11.01%
95.3th percentile
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.4.2 | 10.4.2 |
| apple | mac_os_x_server | < 10.4.2 | 10.4.2 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | krb5 | < krb5 1.3.6-4 (bookworm) | krb5 1.3.6-4 (bookworm) |
| mit | kerberos_5 | <= 1.4.1 | — |
| mit | krb5 | >= 0 < 1.3.6-4 | 1.3.6-4 |
| mit | krb5 | >= 0 < 1.3.6-4 | 1.3.6-4 |
| mit | krb5 | >= 0 < 1.3.6-4 | 1.3.6-4 |
| mit | krb5 | >= 0 < 1.3.6-4 | 1.3.6-4 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerable function is krb5_recvauth(); monitor for exploitation attempts targeting this function in daemons that call it, specifically kpropd, klogind, and kshd ↗
- →The vulnerability is a double-free in krb5_recvauth triggered via certain error conditions over the network; watch for anomalous/malformed Kerberos authentication traffic to KDC and rsh-server daemons ↗
- ·Affected versions are MIT Kerberos 5 (krb5) 1.4.1 and earlier; Debian fixed in package version 1.3.6-4 ↗
- ·The vulnerable daemons are kpropd (krb5-kdc package), klogind, and kshd (krb5-rsh-server package); all daemons calling krb5_recvauth() are at risk ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8MEDIUM
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Kerberos vulnerabilities
vendor_ubuntu·2005-12-06·CVSS 7.5
CVE-2005-0468 [HIGH] Kerberos vulnerabilities
Title: Kerberos vulnerabilities
Summary: Kerberos vulnerabilities
Gaël Delalleau discovered a buffer overflow in the env_opt_add()
function of the Kerberos 4 and 5 telnet clients. By sending specially
crafted replies, a malicious telnet server could exploit this to
execute arbitrary code with the privileges of the user running the
telnet client. (CVE-2005-0468)
Gaël Delalleau discovered a buffer overflow in the handling of the
LINEMODE suboptions in the telnet clients of Kerberos 4 and 5. By
sending a specially constructed reply containing a large number of SLC
(Set Local Character) commands, a remote attacker (i. e. a malicious
telnet server) could execute arbitrary commands with the privileges of
the user running the telnet client. (CVE-2005-0469)
Daniel Wachdorf discovered two remot
Red Hat
security flaw
vendor_redhat·2005-07-12·CVSS 9.8
CVE-2005-1689 [CRITICAL] security flaw
security flaw
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
Debian
CVE-2005-1689: krb5 - Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5)...
vendor_debian·2005·CVSS 9.8
CVE-2005-1689 [CRITICAL] CVE-2005-1689: krb5 - Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5)...
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
Scope: local
bookworm: resolved (fixed in 1.3.6-4)
bullseye: resolved (fixed in 1.3.6-4)
forky: resolved (fixed in 1.3.6-4)
sid: resolved (fixed in 1.3.6-4)
trixie: resolved (fixed in 1.3.6-4)
GHSA
GHSA-8mfg-j523-2x92: Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1
ghsa_unreviewed·2022-05-03
CVE-2005-1689 [HIGH] CWE-119 GHSA-8mfg-j523-2x92: Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
OSV
CVE-2005-1689: Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1
osv·2005-07-18·CVSS 9.8
CVE-2005-1689 [CRITICAL] CVE-2005-1689: Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
No detection rules found.
No public exploits indexed.
ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000993http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2005/Aug/msg00000.htmlhttp://marc.info/?l=bugtraq&m=112119974704542&w=2http://secunia.com/advisories/16041http://secunia.com/advisories/17135http://secunia.com/advisories/17899http://secunia.com/advisories/22090http://securitytracker.com/id?1014461http://sunsolve.sun.com/search/document.do?assetkey=1-26-101810-1http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txthttp://www.debian.org/security/2005/dsa-757http://www.gentoo.org/security/en/glsa/glsa-200507-11.xmlhttp://www.kb.cert.org/vuls/id/623332http://www.novell.com/linux/security/advisories/2005_17_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2005-562.htmlhttp://www.redhat.com/support/errata/RHSA-2005-567.htmlhttp://www.securityfocus.com/archive/1/446940/100/0/threadedhttp://www.securityfocus.com/bid/14239http://www.trustix.org/errata/2005/0036http://www.turbolinux.com/security/2005/TLSA-2005-78.txthttp://www.vupen.com/english/advisories/2005/1066http://www.vupen.com/english/advisories/2006/3776https://exchange.xforce.ibmcloud.com/vulnerabilities/21055https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9819https://usn.ubuntu.com/224-1/ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000993http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2005/Aug/msg00000.htmlhttp://marc.info/?l=bugtraq&m=112119974704542&w=2http://secunia.com/advisories/16041http://secunia.com/advisories/17135http://secunia.com/advisories/17899http://secunia.com/advisories/22090http://securitytracker.com/id?1014461http://sunsolve.sun.com/search/document.do?assetkey=1-26-101810-1http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txthttp://www.debian.org/security/2005/dsa-757http://www.gentoo.org/security/en/glsa/glsa-200507-11.xmlhttp://www.kb.cert.org/vuls/id/623332http://www.novell.com/linux/security/advisories/2005_17_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2005-562.htmlhttp://www.redhat.com/support/errata/RHSA-2005-567.htmlhttp://www.securityfocus.com/archive/1/446940/100/0/threadedhttp://www.securityfocus.com/bid/14239http://www.trustix.org/errata/2005/0036http://www.turbolinux.com/security/2005/TLSA-2005-78.txthttp://www.vupen.com/english/advisories/2005/1066http://www.vupen.com/english/advisories/2006/3776https://exchange.xforce.ibmcloud.com/vulnerabilities/21055https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9819https://usn.ubuntu.com/224-1/
2005-07-18
Published