CVE-2004-0644: Medium severity MIT Kerberos 5 vulnerability
Published Sep 10, 2004
·Updated
The asn1bufskiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.
Affected Software
13 affected components
MIT Kerberos 5=1.2.2
MIT Kerberos 5=1.2.3
MIT Kerberos 5=1.2.4
MIT Kerberos 5=1.2.5
MIT Kerberos 5=1.2.6
MIT Kerberos 5=1.2.7
MIT Kerberos 5=1.2.8
MIT Kerberos 5=1.3-alpha1
MIT Kerberos 5=1.3
MIT Kerberos 5=1.3.1
MIT Kerberos 5=1.3.2
MIT Kerberos 5=1.3.3
MIT Kerberos 5=1.3.4
Remediation
Patch Available
Patch Available
Event History
Sep 10, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0644?
CVE-2004-0644 is classified as a denial of service vulnerability that can cause an infinite loop.
2
How do I fix CVE-2004-0644?
To fix CVE-2004-0644, upgrade to a version of MIT Kerberos 5 that is not affected, specifically version 1.3.5 or later.
3
Which versions of MIT Kerberos 5 are affected by CVE-2004-0644?
CVE-2004-0644 affects MIT Kerberos 5 versions 1.2.2 through 1.3.4.
4
What type of attack is associated with CVE-2004-0644?
CVE-2004-0644 is associated with remote denial of service attacks leveraging specific BER encoding.
5
Is CVE-2004-0644 a local or remote vulnerability?
CVE-2004-0644 is a remote vulnerability that allows attackers to affect the system from a distance.