|
A remote overflow exists in Kerberos 5. Kerberos fails to check the string length in the functions aname_replacer(), do_replacement() and rule_an_to_ln() resulting in a heap buffer overflow. With a specially crafted request, an attacker can gain remote access as root resulting in a loss of confidentiality, integrity, and/or availability. This vulnerability only exists when the software is used with a non-standard configuration. Please see the MIT release notes for the details.
|