CyberSec.Space Logo
Back to CVE Browser

CVE-2002-1235

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0460%
EPSS Percentile6.13th
PublishedNov 4, 2002
Last ModifiedApr 16, 2026

Vulnerability Description

The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

Affected Platforms (CPE)

πŸ“¦
Kth

Kth Kerberos 4

< 1.2.1
πŸ“¦
Kth

Kth Kerberos 5

< 0.5.1
πŸ“¦
Mit

Kerberos 5

>= 1.0 and <= 1.2.6
πŸ’»
Debian

Debian Linux

= 3.0

References & Advisories

Related Vulnerabilities