4.6
CVSSv2

CVE-2004-0643

Published: 28/09/2004 Updated: 02/02/2021
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and previous versions may allow local users to execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mit kerberos 5

debian debian linux 3.0

redhat enterprise linux desktop 3.0

redhat enterprise linux server 3.0

redhat enterprise linux workstation 3.0

Vendor Advisories

Synopsis krb5 security update Type/Severity Security Advisory: Critical Topic Updated Kerberos (krb5) packages that correct double-free and ASN1parsing bugs are now available for Red Hat Enterprise Linux Description Kerberos is a networked authentication system that uses a trusted thirdpa ...
Synopsis krb5 security update Type/Severity Security Advisory: Critical Topic Updated krb5 packages that improve client responsiveness and fix severalsecurity issues are now available for Red Hat Enterprise Linux 3 Description Kerberos is a networked authentication system that uses a trust ...
Two vulnerabilities in the Massachusetts Institute of Technology (MIT) Kerberos 5 implementation that affect Cisco VPN 3000 Series Concentrators have been announced by the MIT Kerberos Team Cisco VPN 3000 Series Concentrators authenticating users against a Kerberos Key Distribution Center (KDC) may be vulnerable to remote code exec ...