CVE-2004-1189
The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- mit/kerberos 5
- Source
- cve@mitre.org
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000917Broken Link
- http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=110358420909358&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=110548298407590&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2004-004-pwhist.txtPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:156Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2005-012.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2005-045.htmlThird Party Advisory
- http://www.trustix.org/errata/2004/0069Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18621Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11911Broken Link, Third Party Advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000917Broken Link
- http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=110358420909358&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=110548298407590&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2004-004-pwhist.txtPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:156Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2005-012.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2005-045.htmlThird Party Advisory
- http://www.trustix.org/errata/2004/0069Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18621Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11911Broken Link, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.