CVE-2002-1235 heimdal

Metadata

critical
10.0
heimdal
CVE-2002-1235
2017-06-18 07:03
CVE-2002-1235 krb5
2017-06-16 18:42
2017-04-01 19:11
2017-01-05 20:15

Description

The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
buster heimdal 0.4e-22
jessie heimdal 0.4e-22
sid heimdal 0.4e-22
stretch heimdal 0.4e-22
wheezy heimdal 0.4e-22