---

MIT: Buffer Overrun Vulnerabilities In Kerberos

“Serious buffer overrun vulnerabilities exist in many
implementations of Kerberos 4, including implementations included
for backwards compatibility in Kerberos 5 implementations. Other
less serious buffer overrun vulnerabilites have also been
discovered. ALL KNOWN KERBEROS 4 IMPLEMENTATIONS derived from MIT
sources are believed to be vulnerable.

IMPACT:

  • A remote user may gain unauthorized root access to a machine
    running services authenticated with Kerberos 4.
  • A remote user may gain unauthorized root access to a machine
    running krshd, regardless of whether the program is configured to
    accept Kerberos 4 authentication.
  • A local user may gain unauthorized root access by exploiting
    v4rcp or ksu.”

Complete
Story

Get the Free Newsletter!

Subscribe to Developer Insider for top news, trends, & analysis