CVE-2000-0549: Medium severity Cygnus Cygnus Network Security vulnerability
Kerberos 4 KDC program does not properly check for null termination of AUTHMSGKDCREQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0549?
CVE-2000-0549 is classified as a denial of service vulnerability that can disrupt the availability of the Kerberos 4 KDC program.
How do I fix CVE-2000-0549?
To fix CVE-2000-0549, ensure that you apply the latest patches provided by your software vendor for affected versions of Kerberos.
What systems are affected by CVE-2000-0549?
CVE-2000-0549 affects versions 4.0 and 5.0 of Cygnus Network Security and MIT Kerberos 5 versions 1.0, 1.1, and 1.1.1.
Is CVE-2000-0549 exploitable remotely?
Yes, CVE-2000-0549 can be exploited remotely by attackers sending malformed AUTH_MSG_KDC_REQUEST requests.
What type of attack does CVE-2000-0549 facilitate?
CVE-2000-0549 facilitates denial of service attacks that can cause the Kerberos KDC to crash or become unresponsive.