CVE-2005-1174: Medium severity mit kerberos 5 vulnerability
Published Jul 16, 2005
·Updated
MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.
Affected Software
9 affected components
MIT Kerberos 5=1.3
MIT Kerberos 5=1.3.1
MIT Kerberos 5=1.3.2
MIT Kerberos 5=1.3.3
MIT Kerberos 5=1.3.4
MIT Kerberos 5=1.3.5
MIT Kerberos 5=1.3.6
MIT Kerberos 5=1.4
MIT Kerberos 5=1.4.1
Remediation
Patch Available
Event History
Jul 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1174?
CVE-2005-1174 has a severity level that can cause a denial of service due to an application crash.
2
How do I fix CVE-2005-1174?
To fix CVE-2005-1174, upgrade your MIT Kerberos 5 installation to version 1.4.2 or later.
3
Which versions of MIT Kerberos 5 are affected by CVE-2005-1174?
CVE-2005-1174 affects MIT Kerberos 5 versions from 1.3 through 1.4.1.
4
What type of attack does CVE-2005-1174 represent?
CVE-2005-1174 represents a denial of service attack that can be executed remotely.
5
Can CVE-2005-1174 be exploited without authentication?
Yes, CVE-2005-1174 can be exploited without authentication through a specific valid TCP connection.