CVE-2004-0642: Double Free
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0642?
CVE-2004-0642 is considered a critical vulnerability that allows for arbitrary code execution by remote attackers.
How do I fix CVE-2004-0642?
To fix CVE-2004-0642, upgrade MIT Kerberos 5 to version 1.3.5 or later.
What systems are affected by CVE-2004-0642?
CVE-2004-0642 affects MIT Kerberos 5 version 1.3.4 and earlier across various operating systems including Debian and Red Hat.
What kind of attacks can be executed through CVE-2004-0642?
CVE-2004-0642 can be exploited by attackers to execute arbitrary code remotely, posing a significant security risk.
Is CVE-2004-0642 specific to certain versions of Kerberos?
Yes, CVE-2004-0642 specifically targets MIT Kerberos 5 versions 1.3.4 and earlier.