[34811] in bugtraq

home help back first fref pref prev next nref lref last post

Advisory: Heimdal kadmind version4 remote heap overflow

daemon@ATHENA.MIT.EDU (Evgeny Demidov)
Thu May 6 13:07:50 2004

From: "Evgeny Demidov" <demidov@gleg.net>
To: full-disclosure@lists.netsys.com
Cc: bugtraq@securityfocus.com
Date: Thu, 06 May 2004 02:47:22 +0400
Message-ID: <web-35564485@cgp.agava.net>
In-Reply-To: <20040505215246.GA77284@madman.celabo.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="KOI8-R"; format="flowed"
Content-Transfer-Encoding: 8bit


Name:          Heimdal kadmind version4 remote heap 
overflow
Date:          6 May 2004
CVE candidate: CAN-2004-0434
Author:        Evgeny Demidov

Description:

There exists a remote preauth heap overflow vulnerability 
in Heimdal kadmind version4 support.
All versions of Heimdal including 0.6.1 are known to be 
vulnerable.

Its recommended to disable Kerberos 4 support by runing 
kadmind with --no-kerberos4 option.

Fix:

FreeBSD has issued an advisory:
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:09.kadmind.asc

Latest Heimdal snapshot also fixes the problem.

History:

The vulnerability has been discovered several months ago 
by Evgeny Demidov during Heimdal source code audit.

The details of the vulnerability has been made availabe to 
VulnDisco clients two weeks ago.

Thanks:

Heimdal development team has been ready with a patch in a 
couple of hours after initial contact.

home help back first fref pref prev next nref lref last post