Oval Definition:oval:org.mitre.oval:def:4936
Revision Date:2005-02-23Version:15
Title:Kerberos 5 KDC ASN.1 Error Handling Double-free Vulnerabilities
Description:Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2004-0642
Platform(s):Sun Solaris 9
Product(s):Kerberos5
Definition Synopsis
  • Software section
  • Solaris 9 Installed
  • AND Kerberos 5 installed
  • AND NOT Patch 112908-15 or later installed
  • AND Configuration section
  • /etc/krb5/krb5.conf is configured with a kerberos domain
  • BACK