VDB
CVE-2005-1175
CVE-2005-1175
PUBLISHED
CVSS 7.5 HIGH
Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.
EPSS 8.43% · 94.8th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
8.43%
94.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| mit | kerberos_5 | 1.3, 1.3.1, 1.3.2 |
Timeline
- Jul 17, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- Jun 7, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- 20364 third-party-advisory
- SUSE-SR:2005:017 vendor-advisory
- 20050703-01-U vendor-advisory
- VU#885830 third-party-advisory
- RHSA-2005:567 vendor-advisory
- oval:org.mitre.oval:def:736 vdb
- 14236 vdb
- 1014460 vdb
- RHSA-2005:562 vendor-advisory
- 101809 vendor-advisory
- USN-224-1 vendor-advisory
- APPLE-SA-2005-08-17 vendor-advisory
- 2005-0036 vendor-advisory
- http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html technical
- http://marc.info/?l=bugtraq&m=112122123211974&w=2 technical
- http://secunia.com/advisories/17135 technical
- http://secunia.com/advisories/17899 technical
- http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-002-kdc.txt patch
- http://www.turbolinux.com/security/2005/TLSA-2005-78.txt technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9902 technical
…and 8 more