Description
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
Affected products
- cygnus / cygnus_network_security4.0 – 4.0
- cygnus / kerbnet5.0 – 5.0
- MIT / kerberos4.0 – 4.0
- MIT / Kerberos 51.0 – 1.0
- MIT / Kerberos 51.1.1 – 1.1.1
- RedHat / linux6.2 – 6.2
- RedHat / linux6.2 – 6.2
- RedHat / linux6.2 – 6.2
Exploits & proofs of concept
- exploit-dbCygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Local Buffer Overflow (2)by Jim Paris
- exploit-dbCygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (1)by duke
- exploit-dbCygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (3)by Jim Paris
References
Updated 18m ago · 8 sources