CVE-2000-0550: Medium severity cygnus kerbnet vulnerability
Published Jun 9, 2000
·Updated
Kerberos 4 KDC program improperly frees memory twice (aka "double-free"), which allows remote attackers to cause a denial of service.
Affected Software
6 affected components
Cygnus Cygnus Network Security=4.0
Cygnus Kerbnet=5.0
MIT Kerberos=4.0
MIT Kerberos 5=1.0
MIT Kerberos 5=1.1
MIT Kerberos 5=1.1.1
Remediation
Patch Available
Event History
Jun 9, 2000
CVE Published
04:00 AM
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0550?
CVE-2000-0550 is classified as a denial of service vulnerability.
2
How do I fix CVE-2000-0550?
To fix CVE-2000-0550, you should upgrade to the latest version of the affected Kerberos software.
3
What software is affected by CVE-2000-0550?
CVE-2000-0550 affects Kerbnet 5.0, Cygnus Network Security 4.0, and various versions of MIT Kerberos 4.0 and 5.x.
4
What type of attack does CVE-2000-0550 enable?
CVE-2000-0550 allows attackers to cause a denial of service through a double-free memory vulnerability.
5
Can CVE-2000-0550 be exploited remotely?
Yes, CVE-2000-0550 can be exploited remotely by attackers to affect the availability of the service.