CVE-2004-0434: Buffer Overflow
Published May 12, 2004
·Updated
k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow.
Affected Software
2 affected components
Heimdal Project Heimdal<0.6.2
Debian Debian Linux=3.0
Remediation
Patch Available
Event History
May 12, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0434?
CVE-2004-0434 has a high severity due to the potential for remote attackers to execute arbitrary code.
2
How do I fix CVE-2004-0434?
To fix CVE-2004-0434, update Heimdal to version 0.6.2 or later, or apply any available patches from your operating system vendor.
3
Which software is affected by CVE-2004-0434?
CVE-2004-0434 affects Heimdal versions prior to 0.6.2 and Debian Linux 3.0.
4
What type of vulnerability is CVE-2004-0434?
CVE-2004-0434 is a heap-based buffer overflow vulnerability.
5
Can CVE-2004-0434 be exploited remotely?
Yes, CVE-2004-0434 can be exploited remotely through a crafted Kerberos 4 compatibility administration request.