First published: Fri Sep 10 2004(Updated: )
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MIT Kerberos 5 | <=1.3.4 | |
Debian GNU/Linux | =3.0 | |
redhat enterprise Linux desktop | =3.0 | |
redhat enterprise Linux server | =3.0 | |
redhat enterprise Linux workstation | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0642 is considered a critical vulnerability that allows for arbitrary code execution by remote attackers.
To fix CVE-2004-0642, upgrade MIT Kerberos 5 to version 1.3.5 or later.
CVE-2004-0642 affects MIT Kerberos 5 version 1.3.4 and earlier across various operating systems including Debian and Red Hat.
CVE-2004-0642 can be exploited by attackers to execute arbitrary code remotely, posing a significant security risk.
Yes, CVE-2004-0642 specifically targets MIT Kerberos 5 versions 1.3.4 and earlier.