Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MIT Kerberos 5 Administration Library Add_To_History Heap-Based Buffer Overflow Vulnerability

It is reported that the MIT Kerberos 5 administration library is affected by a heap-based buffer overflow vulnerability. The vulnerability presents itself in the 'add_to_history()' function of the 'svr_principal.c' source file. The vulnerability exists due to an indexing error that occurs under certain circumstances.

An authenticated attacker may potentially exploit this vulnerability on a Key Distribution Center (KDC) to execute arbitrary code in the context of the vulnerable service, ultimately resulting in the compromise of an entire Kerberos realm.







 

Privacy Statement
Copyright 2008, SecurityFocus