SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-1235

The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before…

HIGH 10.0EPSS 15.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 15.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
15.10% probability · 97th percentile
CISA KEV
Not listed
Affected
kth/kth kerberos 4 · kth/kth kerberos 5 · mit/kerberos 5 · debian/debian linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.