FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0644

This CVE name corresponds to:

Entered Topic
2004-08-31 krb5 -- ASN.1 decoder denial-of-service vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0644
Phase Assigned(20040708)

Description

The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.

References

Source Reference
CONFIRM http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-003-asn1.txt
CERT TA04-247A
CERT-VN VU#550464
CONECTIVA CLA-2004:860
DEBIAN DSA-543
GENTOO GLSA-200409-09
REDHAT RHSA-2004:350
TRUSTIX 2004-0045
BUGTRAQ 20040913 [OpenPKG-SA-2004.039] OpenPKG Security Advisory (kerberos)
BID 11079
OVAL oval:org.mitre.oval:def:2139
OVAL oval:org.mitre.oval:def:10014
XF kerberos-asn1-library-dos(17160)