PT-2004-1058 · Mit+1 · Krb5-Devel+5

CVE-2004-0642

·

Publicado

2004-09-10

·

Atualizado

2024-02-02

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions krb5-devel versions 1.2.2 krb5-server versions 1.2.2 krb5-libs versions 1.2.2 krb5-workstation versions 1.2.2 MIT Kerberos 5 (krb5) versions prior to 1.3.4
Description The issue concerns multiple vulnerabilities in the krb5 package of Red Hat Enterprise Linux and MIT Kerberos 5 (krb5), which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, double free vulnerabilities exist in the error handling code for ASN.1 decoders in the Key Distribution Center (KDC) library and the client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier, potentially allowing remote attackers to execute arbitrary code.
Recommendations For krb5-devel version 1.2.2, update to a version later than 1.2.2. For krb5-server version 1.2.2, update to a version later than 1.2.2. For krb5-libs version 1.2.2, update to a version later than 1.2.2. For krb5-workstation version 1.2.2, update to a version later than 1.2.2. For MIT Kerberos 5 (krb5) versions prior to 1.3.4, update to version 1.3.4 or later. As a temporary workaround, consider restricting access to the Key Distribution Center (KDC) library and the client library until a patch is available.

Correção

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06282
BDU:2015-06285
BDU:2015-06289
BDU:2015-06293
CVE-2004-0642
DSA-543-1
RHSA-2004:350

Produtos afetados

Mit Kerberos 5
Red Hat
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation