Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Kerberos 5.x
This vulnerability report for Kerberos 5.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Kerberos 5.x then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor N/A

Product Link View Here (Link to external site)

Affected By 21 Secunia advisories
26 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 10% (2 of 21 Secunia advisories)

Most Critical Unpatched
The most severe unpatched Secunia advisory affecting Kerberos 5.x, with all vendor patches applied, is rated Less critical .




21 Secunia Advisories in 2003-2009
Secunia has issued a total of 21 Secunia advisories in 2003-2009 for Kerberos 5.x. Currently, 10% (2 out of 21) are marked as unpatched with the most severe being rated Less critical

More information about the specific Secunia advisories affecting Kerberos 5.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



Kerberos Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 1 in 2009. 3,207 views.
Release Date:
2009-03-25
Secunia Advisory ID:
SA34347
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
DoS
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Kerberos, which can be exploited by malicious people to potentially disclose sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system. [Read More]


Kerberos Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 1 in 2008. 8,607 views.
Release Date:
2008-03-19
Secunia Advisory ID:
SA29428
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
DoS
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Kerberos, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system. [Read More]


Kerberos Multiple Vulnerabilities
Vendor Workaround. Secunia Advisory 1 of 5 in 2007. 10,441 views.
Release Date:
2007-09-05
Secunia Advisory ID:
SA26676
Solution Status:
Vendor Workaround
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Kerberos, which can be exploited by malicious users and malicious people to compromise a vulnerable system. [Read More]


Kerberos Multiple Vulnerabilities
Vendor Workaround. Secunia Advisory 2 of 5 in 2007. 9,849 views.
Release Date:
2007-06-27
Secunia Advisory ID:
SA25800
Solution Status:
Vendor Workaround
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Kerberos, which can be exploited by malicious users and malicious people to compromise a vulnerable system. [Read More]


Kerberos Multiple Vulnerabilities
Vendor Workaround. Secunia Advisory 3 of 5 in 2007. 11,079 views.
Release Date:
2007-04-04
Secunia Advisory ID:
SA24740
Solution Status:
Vendor Workaround
Criticality:
Impact:
Security Bypass
DoS
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Kerberos, which can be exploited by malicious users to cause a DoS or compromise a vulnerable system and by malicious people to bypass certain security restrictions. [Read More]


Kerberos kadmind "mechglue" Code Execution Vulnerability
Vendor Patch. Secunia Advisory 4 of 5 in 2007. 10,849 views.
Release Date:
2007-01-10
Secunia Advisory ID:
SA23690
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Kerberos, which can potentially be exploited by malicious people to compromise a vulnerable system. [Read More]


Kerberos kadmind xprt->xp_auth Code Execution Vulnerability
Vendor Patch. Secunia Advisory 5 of 5 in 2007. 12,277 views.
Release Date:
2007-01-10
Secunia Advisory ID:
SA23696
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Kerberos, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system. [Read More]


Kerberos V5 setuid Security Issue
Vendor Patch. Secunia Advisory 1 of 1 in 2006. 9,620 views.
Release Date:
2006-08-09
Secunia Advisory ID:
SA21402
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A security issue has been reported in Kerberos, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges. [Read More]


Kerberos V5 Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 3 in 2005. 17,859 views.
Release Date:
2005-07-13
Secunia Advisory ID:
SA16041
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Kerberos, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system. [Read More]


Kerberos V5 Telnet Client Information Disclosure Weakness
Unpatched. Secunia Advisory 2 of 3 in 2005. 11,805 views.
Release Date:
2005-06-15
Secunia Advisory ID:
SA15709
Solution Status:
Unpatched
Criticality:
Impact:
Exposure of system information
Where:
From remote
Short Description:
Gaël Delalleau has reported a weakness in Kerberos V5, which can be exploited by malicious people to gain knowledge of various information. [Read More]


MIT Kerberos Telnet Client Buffer Overflow Vulnerabilities
Vendor Patch. Secunia Advisory 3 of 3 in 2005. 20,219 views.
Release Date:
2005-03-29
Secunia Advisory ID:
SA14745
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Gaël Delalleau has reported two vulnerabilities in Kerberos V5, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Kerberos V5 "libkadm5srv" Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 1 of 4 in 2004. 15,425 views.
Release Date:
2004-12-21
Secunia Advisory ID:
SA13592
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Michael Tautschnig has reported a vulnerability in Kerberos V5, which potentially can be exploited by malicious users to compromise a vulnerable system. [Read More]


Kerberos V5 "send-pr.sh" Script Insecure Temporary File Creation
Unpatched. Secunia Advisory 2 of 4 in 2004. 10,060 views.
Release Date:
2004-10-25
Secunia Advisory ID:
SA12967
Solution Status:
Unpatched
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Kerberos V5, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges. [Read More]


Kerberos V5 Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 3 of 4 in 2004. 16,406 views.
Release Date:
2004-09-01
Secunia Advisory ID:
SA12408
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Kerberos V5, where the most serious potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]


Kerberos V5 "krb5_aname_to_localname()" Buffer Overflow Vulnerabilities
Vendor Patch. Secunia Advisory 4 of 4 in 2004. 14,089 views.
Release Date:
2004-06-02
Secunia Advisory ID:
SA11753
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Vulnerabilities have been discovered in Kerberos V5, which can be exploited by malicious users to compromise a vulnerable system. [Read More]


Kerberos integer overflow in XDR code
Vendor Patch. Secunia Advisory 1 of 5 in 2003. 7,731 views.
Release Date:
2003-03-21
Secunia Advisory ID:
SA8370
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Kerberos uses code that has been derived from SUNRPC. This code suffers similar problems as those recently discovered in RPC XDR. This vulnerability could be used to crash Kerberos and possibly execute arbitrary code, however, this has not been proven yet. [Read More]


Kerberos principal name buffer overflow
Vendor Patch. Secunia Advisory 2 of 5 in 2003. 7,377 views.
Release Date:
2003-03-21
Secunia Advisory ID:
SA8369
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Kerberos has been found vulnerable to a buffer overflow and buffer underrun problem, this could cause a Denial of Service and could possibly be used to execute arbitrary code as well, however, this has not been proven. [Read More]


Kerberos cryptographic implementation flaws
Vendor Patch. Secunia Advisory 3 of 5 in 2003. 7,573 views.
Release Date:
2003-03-18
Secunia Advisory ID:
SA8319
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Spoofing
Exposure of system information
Where:
From remote
Short Description:
A paper has been published detailing weaknesses and flaws with the implementation of cryptography in Kerberos V4. This also affects Kerberos V5 due to backward compatibility. [Read More]


Kerberos FTP client arbitrary command execution
Partial Fix. Secunia Advisory 4 of 5 in 2003. 6,886 views.
Release Date:
2003-01-29
Secunia Advisory ID:
SA7965
Solution Status:
Partial Fix
Criticality:
Impact:
System access
Where:
From remote
Short Description:
The Kerberos FTP client is vulnerable to a 6 year old vulnerability. [Read More]


Kerberos multiple vulnerabilities
Vendor Patch. Secunia Advisory 5 of 5 in 2003. 6,636 views.
Release Date:
2003-01-29
Secunia Advisory ID:
SA7964
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Kerberos is vulnerable to multiple issues. [Read More]


Kerberos remotely exploitable buffer overflow
Vendor Patch. Secunia Advisory 1 of 1 in 2002. 6,605 views.
Release Date:
2002-10-23
Secunia Advisory ID:
SA7376
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
It is possible to cause a stack overflow in kerberos kadmind4, this allows attackers to execute arbitrary code. [Read More]