Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.52267
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: krb5, krb5-beta
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following packages are affected:

krb5
krb5-beta

CVE-2004-1189
The add_to_history function in svr_principal.c in libkadm5srv for MIT
Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does
not properly track the password policy's history count and the maximum
number of keys, which can cause an array index out-of-bounds error
and may allow authenticated users to execute arbitrary code via a
heap-based buffer overflow.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2004-1189
http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
Bugtraq: 20041220 MITKRB5-SA-2004-004: heap overflow in libkadm5srv (Google Search)
http://marc.info/?l=bugtraq&m=110358420909358&w=2
Bugtraq: 20050110 [USN-58-1] MIT Kerberos server vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=110548298407590&w=2
Conectiva Linux advisory: CLA-2005:917
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000917
http://www.mandriva.com/security/advisories?name=MDKSA-2004:156
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11911
http://www.redhat.com/support/errata/RHSA-2005-012.html
http://www.redhat.com/support/errata/RHSA-2005-045.html
http://www.trustix.org/errata/2004/0069
XForce ISS Database: kerberos-libkadm5srv-bo(18621)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18621
CopyrightCopyright (C) 2008 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.