First published: Fri Jun 09 2000(Updated: )
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MIT Kerberos 5 Application | =1.1 | |
MIT Kerberos 5 Application | =1.1.1 | |
MIT Kerberos 5 Application | >=1.0<=1.0.7 | |
MIT Kerberos 5 Application | =4.0-patch10 | |
MIT Kerberos 5 Application | =4.0 | |
Cygnus Network Security | ||
kerbnet | ||
MIT Kerberos 5 Application | <4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0548 is a high severity vulnerability due to the potential for remote denial of service attacks.
To fix CVE-2000-0548, update to a patched version of the MIT Kerberos software that addresses the buffer overflow issue.
CVE-2000-0548 affects various versions of MIT Kerberos 4 and 5, specifically those below version 1.1.2.
Yes, CVE-2000-0548 can be exploited remotely by attackers targeting the Kerberos 4 KDC program.
Exploiting CVE-2000-0548 can lead to a denial of service, disrupting authentication services across a network.