Name | CVE-2002-1235 |
Description | The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-183, DSA-184, DSA-185 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
heimdal (PTS) | jessie, jessie (lts) | 1.6~rc2+dfsg-9+deb8u3 | fixed |
stretch (security) | 7.1.0+dfsg-13+deb9u3 | fixed | |
stretch (lts), stretch | 7.1.0+dfsg-13+deb9u4 | fixed | |
buster (security), buster, buster (lts) | 7.5.0+dfsg-3+deb10u2 | fixed | |
bullseye (security), bullseye | 7.7.0+dfsg-2+deb11u3 | fixed | |
bookworm | 7.8.git20221117.28daf24+dfsg-2 | fixed | |
sid, trixie | 7.8.git20221117.28daf24+dfsg-8 | fixed | |
krb5 (PTS) | jessie, jessie (lts) | 1.12.1+dfsg-19+deb8u9 | fixed |
stretch (security) | 1.15-1+deb9u3 | fixed | |
stretch (lts), stretch | 1.15-1+deb9u6 | fixed | |
buster, buster (lts) | 1.17-3+deb10u7 | fixed | |
buster (security) | 1.17-3+deb10u6 | fixed | |
bullseye (security), bullseye | 1.18.3-6+deb11u5 | fixed | |
bookworm (security), bookworm | 1.20.1-2+deb12u2 | fixed | |
sid, trixie | 1.21.3-3 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
heimdal | source | woody | 0.4e-7.woody.5 | DSA-185 | ||
heimdal | source | (unstable) | 0.4e-22 | |||
krb4 | source | woody | 1.1-8-2.2 | DSA-184 | ||
krb4 | source | (unstable) | 1.1-11-8 | |||
krb5 | source | woody | 1.2.4-5woody3 | DSA-183 | ||
krb5 | source | (unstable) | 1.2.6-2 |