Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.
                
            References
                    | Link | Resource | 
|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html | Broken Link | 
| http://ciac.llnl.gov/ciac/bulletins/k-051.shtml | Broken Link | 
| http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt | Patch Vendor Advisory | 
| http://www.cert.org/advisories/CA-2000-11.html | Third Party Advisory US Government Resource | 
| http://www.securityfocus.com/bid/1338 | Third Party Advisory VDB Entry | 
| http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html | Broken Link | 
| http://ciac.llnl.gov/ciac/bulletins/k-051.shtml | Broken Link | 
| http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt | Patch Vendor Advisory | 
| http://www.cert.org/advisories/CA-2000-11.html | Third Party Advisory US Government Resource | 
| http://www.securityfocus.com/bid/1338 | Third Party Advisory VDB Entry | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    20 Nov 2024, 23:32
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html - Broken Link | |
| References | () http://ciac.llnl.gov/ciac/bulletins/k-051.shtml - Broken Link | |
| References | () http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt - Patch, Vendor Advisory | |
| References | () http://www.cert.org/advisories/CA-2000-11.html - Third Party Advisory, US Government Resource | |
| References | () http://www.securityfocus.com/bid/1338 - Third Party Advisory, VDB Entry | 
Information
                Published : 2000-06-09 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2000-0546
Mitre link : CVE-2000-0546
CVE.ORG link : CVE-2000-0546
JSON object : View
Products Affected
                mit
- kerberos_5
- kerberos
cygnus_network_security_project
- cygnus_network_security
kerbnet_project
- kerbnet
CWE
                
                    
                        
                        CWE-120
                        
            Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
