20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROSmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html CVE-2000-0389
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (1)
Record summary
CVE-2000-0389 has a selected CVSS score of 10.0; EIP currently links 3 catalogued exploits.
Description
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBCygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (1)ExploitDB exploitby dukeNot analyzed1 file
ExploitDBCygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Local Buffer Overflow (2)ExploitDB exploitby Jim ParisNot analyzed1 file
ExploitDBCygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (3)ExploitDB exploitby Jim ParisNot analyzed1 file
References
6FreeBSD-SA-00:20Vendor advisory
http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html CA-2000-06Third-party advisory
http://www.cert.org/advisories/CA-2000-06.html RHSA-2000:025Vendor advisory
http://www.redhat.com/support/errata/RHSA-2000-025.html 1220vdb entry
http://www.securityfocus.com/bid/1220 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0389