First published: Wed May 12 2004(Updated: )
k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
heimdal | <0.6.2 | |
Debian Linux | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0434 has a high severity due to the potential for remote attackers to execute arbitrary code.
To fix CVE-2004-0434, update Heimdal to version 0.6.2 or later, or apply any available patches from your operating system vendor.
CVE-2004-0434 affects Heimdal versions prior to 0.6.2 and Debian Linux 3.0.
CVE-2004-0434 is a heap-based buffer overflow vulnerability.
Yes, CVE-2004-0434 can be exploited remotely through a crafted Kerberos 4 compatibility administration request.