Lucene search

K
osvGoogleOSV:DSA-520
HistoryJun 16, 2004 - 12:00 a.m.

krb5 - buffer overflows

2004-06-1600:00:00
Google
osv.dev
8

0.261 Low

EPSS

Percentile

96.8%

In their advisory MITKRB5-SA-2004-001, the MIT Kerberos announced the
existence of buffer overflow vulnerabilities in the
krb5_aname_to_localname function. This function is only used if
aname_to_localname is enabled in the configuration (this is not
enabled by default).

For the current stable distribution (woody), this problem has been
fixed in version 1.2.4-5woody5.

For the unstable distribution (sid), this problem has been fixed in
version 1.3.3-2.

We recommend that you update your krb5 package.