CVE-2004-0643: Double Free
Published Sep 10, 2004
·Updated
Double free vulnerability in the krb5rdcred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.
Affected Software
5 affected components
MIT Kerberos 5<=1.3.3
Debian Debian Linux=3.0
redhat Enterprise Linux Desktop=3.0
redhat Enterprise Linux Workstation=3.0
redhat Enterprise Linux Server=3.0
Remediation
Event History
Sep 10, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0643?
CVE-2004-0643 has a high severity level due to its potential to allow local users to execute arbitrary code.
2
How do I fix CVE-2004-0643?
To fix CVE-2004-0643, upgrade to a version of MIT Kerberos 5 later than 1.3.3 that no longer contains this vulnerability.
3
Which versions are affected by CVE-2004-0643?
CVE-2004-0643 affects MIT Kerberos 5 versions 1.3.1 and earlier.
4
What is the impact of CVE-2004-0643?
The impact of CVE-2004-0643 allows for arbitrary code execution, which can lead to system compromise.
5
Who is most at risk for CVE-2004-0643?
Local users on systems running vulnerable versions of MIT Kerberos 5 are most at risk from CVE-2004-0643.