Multiple Vendor kadmind Remote Buffer Overflow Vulnerability

BID:6024

Info

Multiple Vendor kadmind Remote Buffer Overflow Vulnerability

Bugtraq ID: 6024
Class: Boundary Condition Error
CVE: CVE-2002-1235
Remote: Yes
Local: No
Published: Oct 21 2002 12:00AM
Updated: Jul 11 2009 06:06PM
Credit: Discovery of vulnerability credited to Johan Danielsson and Love Hornquist-Astrand. Discovery is also credited to Tom Yu and Sam Hartman of MIT.
Vulnerable: OpenBSD OpenBSD 3.2
OpenBSD OpenBSD 3.1
OpenBSD OpenBSD 3.0
NetBSD NetBSD 1.6
NetBSD NetBSD 1.5.3
NetBSD NetBSD 1.5.2
NetBSD NetBSD 1.5.1
NetBSD NetBSD 1.5
MIT Kerberos 5 1.2.6
MIT Kerberos 5 1.2.5
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ Mandriva Linux Mandrake 9.0
+ Redhat Linux 8.0 i386
+ Redhat Linux 8.0
+ Turbolinux Home
+ Turbolinux Turbolinux 10 F...
+ Turbolinux Turbolinux Desktop 10.0
+ Turbolinux Turbolinux Server 8.0
+ Wirex Immunix OS 7+
MIT Kerberos 5 1.2.4
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.3
MIT Kerberos 5 1.2.3
MIT Kerberos 5 1.2.2
+ MandrakeSoft Multi Network Firewall 2.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2
+ Redhat Linux 7.1 ia64
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alpha
+ Redhat Linux 7.1
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0 alpha
+ Redhat Linux 7.0
MIT Kerberos 5 1.2.1
MIT Kerberos 5 1.2
MIT Kerberos 5 1.1.1
- Redhat Linux 7.1 ia64
- Redhat Linux 7.1 i386
- Redhat Linux 7.1 alpha
- Redhat Linux 7.1
- Redhat Linux 7.0 i386
- Redhat Linux 7.0 alpha
- Redhat Linux 7.0
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2 alpha
+ Redhat Linux 6.2
MIT Kerberos 5 1.1
MIT Kerberos 5 1.0.6
MIT Kerberos 5 1.0
MIT Kerberos 4 4.0
MIT Kerberos 4 1.1
MIT Kerberos 4 1.0
KTH Heimdal 0.21
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 IA-32
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
KTH Heimdal 0.5
- Gentoo Linux 1.4 _rc1
- Gentoo Linux 1.2
KTH Heimdal 0.4 e
+ FreeBSD FreeBSD 4.6 -RELEASE
+ FreeBSD FreeBSD 4.6
- FreeBSD FreeBSD 4.4
- FreeBSD FreeBSD 4.3
- FreeBSD FreeBSD 4.2
- FreeBSD FreeBSD 4.1.1
- FreeBSD FreeBSD 4.1
- FreeBSD FreeBSD 4.0
+ SuSE Linux 8.0
KTH Heimdal 0.4 d
+ SuSE Linux 7.3
KTH Heimdal 0.4 c
KTH Heimdal 0.4 b
KTH Heimdal 0.4 a
KTH Heimdal 0.3 e
+ SuSE Linux 7.2
KTH eBones 1.2
Keware Technologies HomeSeer 0.4 e
IBM PSSP 3.5
IBM PSSP 3.4
IBM PSSP 3.2
IBM PSSP 3.1.1
FreeBSD FreeBSD 4.7 -RELEASE
FreeBSD FreeBSD 4.7
FreeBSD FreeBSD 4.6
FreeBSD FreeBSD 4.5
FreeBSD FreeBSD 4.4
FreeBSD FreeBSD 4.3
FreeBSD FreeBSD 4.2
FreeBSD FreeBSD 4.1
FreeBSD FreeBSD 4.0
Not Vulnerable: KTH Heimdal 0.5.1
+ FreeBSD FreeBSD 5.0
KTH eBones 1.2.1
IBM AIX 4.3.3
IBM AIX 4.3.2
IBM AIX 4.3.1
IBM AIX 4.3
IBM AIX 4.2
IBM AIX 4.1
IBM AIX 4.0
IBM AIX 5.1

Exploit / POC

Multiple Vendor kadmind Remote Buffer Overflow Vulnerability

There are rumors of an exploit for this vulnerability circulating in the wild.

Solution / Fix

Multiple Vendor kadmind Remote Buffer Overflow Vulnerability

Solution:
CERT has released an advisory which contains information about various vendors and implementations that are reported to be affected by this vulnerability.

CERT has released a followup advisory which retracts information about the applicability of Debian Security Advisory DSA-178 and associated fixes. SuSE Security Advisory SuSE-SA:2002:034 also does not address this issue.

Debian has released Debian Security Advisory DSA 183-1 which does address this issue for affected MIT Kerberos 5 packages that ship with Debian GNU/Linux 3.0 alias woody. Information on obtaining fixes may be found in the referenced advisory.

NetBSD has released an advisory. NetBSD-current, NetBSD 1.6 and NetBSD 1.5 branches dated 2002-10-22 and later have fixes for this vulnerability. Users are advised to upgrade the crypto/dist/heimdal/kadmin directory in CVS. Further information is available in the referenced advisory.

FreeBSD have addressed this issue as of October 23rd, 2002 for the base Kerberos 4 (kadmind) and Kerberos 5 (k5admind v4 compatibility) daemons. The heimdal and krb5 ports were corrected as of October 24th, 2002. A vendor advisory is reported to be forthcoming.

MIT has released an advisory. Detailed patch information is available in the referenced advisory.

Apple has announced that the Kerberos Administration Daemon was included in Mac OS X 10.0, but was removed in Mac OS X versions 10.1 and later.

SuSE Linux versions 7.2 and ship with Heimdal Kerberos. However, Kerberos 4 support is not enabled.

Gentoo Linux has released an advisory and made fixes available. To update systems, Gentoo Linux users are advised to perform the following update procedures:

emerge rsync
emerge kth-krb
emerge heimdal
emerge clean

Sorcerer Linux has released an advisory and made fixes available. To update systems, Socerer Linux users are advise to perform the following update procedures:

augur synch
augur update

Debian has released Debian Security Advisory DSA 184-1 which addresses the issue for affected MIT Kerberos 4 packages.

Debian has released Debian Security Advisory DSA 185-1 which addresses the issue for affected Heimdal Kerberos packages. Information about obtaining fixes are available in the referenced advisory.

Conectiva Linux has released an advisory. Further information can be obtained from referenced advisory.

RedHat has released a security advisory which addressed the issue for affected MIT Kerberos 5 packages.

FreeBSD has released an advisory. Users are advised to update their ports tree and reinstall the heimdal or krb5 ports or to download and install a patch. Further, detailed information is available in the referenced advisory.

IBM has made APARs available to resolve this issue.

HP has released advisory HPSBTL0211-077 for HP Secure OS advising users to apply the fixes listed in Red Hat advisory RHSA-2002:242-06.

Fixes have been released which address this issue:


OpenBSD OpenBSD 3.2

OpenBSD OpenBSD 3.0

OpenBSD OpenBSD 3.1

KTH Heimdal 0.21

KTH Heimdal 0.4 e

Keware Technologies HomeSeer 0.4 e

MIT Kerberos 4 1.0

MIT Kerberos 4 1.1

MIT Kerberos 5 1.1.1

MIT Kerberos 5 1.2.2

MIT Kerberos 5 1.2.3

MIT Kerberos 5 1.2.4

MIT Kerberos 5 1.2.5

MIT Kerberos 5 1.2.6

IBM PSSP 3.1.1

IBM PSSP 3.2

IBM PSSP 3.4

IBM PSSP 3.5

FreeBSD FreeBSD 4.4

FreeBSD FreeBSD 4.5

FreeBSD FreeBSD 4.6

FreeBSD FreeBSD 4.7

References

Multiple Vendor kadmind Remote Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report