← Back to CVE List
Vulnerability Intelligence Report

CVE-2004-0523

Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:11.67%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
mit kerberos 1.0, 1.0.8, 1.2.2.beta1
mit kerberos_5 1.0, 1.0.6, 1.1, 1.1.1, 1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.3, 1.3.3
sgi propack 2.4, 3.0
sun seam 1.0, 1.0.1, 1.0.2
tinysofa tinysofa_enterprise_server 1.0, 1.0_u1
sun solaris 8.0, 9.0
sun sunos 5.8

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
11.665%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2004-06-03T00:00:00
Published2004-06-03T04:00:00
Patch Date2004-06-01
Last Updated2024-08-08T00:24:25

LINK COPIED TO CLIPBOARD