CVE-2004-0642

MIT Kerberos 5 <1.3.4 - RCE

Title source: llm

Description

Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.

Scores

EPSS 0.2580
EPSS Percentile 96.2%

Classification

CWE
CWE-415
Status draft

Affected Products (5)

mit/kerberos_5 < 1.3.4
debian/debian_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_workstation

Timeline

Published Sep 28, 2004
Tracked Since Feb 18, 2026