LWN.net Logo

heimdal: missing input sanitizing

Package(s):heimdal CVE #(s):CAN-2004-0472
Created:May 18, 2004 Updated:May 27, 2004
Description: Evgeny Demidov discovered a potential buffer overflow in a Kerberos 4 component of heimdal, a free implementation of Kerberos 5. The problem is present in kadmind, a server for administrative access to the Kerberos database. This problem could perhaps be exploited to cause the daemon to read a negative amount of data which could lead to unexpected behavior.
Alerts:
Gentoo 200405-23 2004-05-27
Debian DSA-504-1 2004-05-18

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds