CyberSec.Space Logo
CVEブラウザに戻る

CVE-2002-1235

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0460%
EPSS Percentile6.13th
Published2002年11月4日
Last Modified2026年4月16日

Vulnerability Description

The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

Affected Platforms (CPE)

📦
Kth

Kth Kerberos 4

< 1.2.1
📦
Kth

Kth Kerberos 5

< 0.5.1
📦
Mit

Kerberos 5

>= 1.0 and <= 1.2.6
💻
Debian

Debian Linux

= 3.0

References & Advisories

関連する脆弱性情報