5
CVSSv2

CVE-2004-0644

Published: 28/09/2004 Updated: 21/01/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 up to and including 1.3.4 allows remote malicious users to cause a denial of service (infinite loop) via a certain BER encoding.

Vulnerable Product Search on Vulmon Subscribe to Product

mit kerberos 5 1.2.7

mit kerberos 5 1.2.8

mit kerberos 5 1.2.2

mit kerberos 5 1.3

mit kerberos 5 1.3.1

mit kerberos 5 1.2.5

mit kerberos 5 1.2.6

mit kerberos 5 1.3.4

mit kerberos 5 1.2.3

mit kerberos 5 1.2.4

mit kerberos 5 1.3.2

mit kerberos 5 1.3.3

Vendor Advisories

Synopsis krb5 security update Type/Severity Security Advisory: Critical Topic Updated Kerberos (krb5) packages that correct double-free and ASN1parsing bugs are now available for Red Hat Enterprise Linux Description Kerberos is a networked authentication system that uses a trusted thirdpa ...
Synopsis krb5 security update Type/Severity Security Advisory: Critical Topic Updated krb5 packages that improve client responsiveness and fix severalsecurity issues are now available for Red Hat Enterprise Linux 3 Description Kerberos is a networked authentication system that uses a trust ...
Two vulnerabilities in the Massachusetts Institute of Technology (MIT) Kerberos 5 implementation that affect Cisco VPN 3000 Series Concentrators have been announced by the MIT Kerberos Team Cisco VPN 3000 Series Concentrators authenticating users against a Kerberos Key Distribution Center (KDC) may be vulnerable to remote code exec ...