Vulnerability Description
MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mit | Kerberos 5 | 1.3 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc
- http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
- http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
- http://marc.info/?l=bugtraq&m=112122123211974&w=2
- http://secunia.com/advisories/16041
- http://secunia.com/advisories/17899
- http://secunia.com/advisories/20364
- http://securitytracker.com/id?1014460
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101809-1
- http://web.mit.edu/kerberos/advisories/2005-002-patch_1.4.1.txtPatch
- http://www-1.ibm.com/support/docview.wss?uid=swg1IY85474
- http://www.debian.org/security/2005/dsa-757
- http://www.kb.cert.org/vuls/id/259798PatchThird Party AdvisoryUS Government Resource
- http://www.novell.com/linux/security/advisories/2005_17_sr.html
- http://www.redhat.com/support/errata/RHSA-2005-567.html
FAQ
What is CVE-2005-1174?
CVE-2005-1174 is a vulnerability with a CVSS score of 5.0 (MEDIUM). MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of ...
How severe is CVE-2005-1174?
CVE-2005-1174 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-1174?
Check the references section above for vendor advisories and patch information. Affected products include: Mit Kerberos 5.