MIT Kerberos 5 contains a flaw that may allow buffer overflow. The issue is triggered by applications which require legacy Kerberos 4 authentication. It is possible that the flaw may allow an attacker to gain root access on affected machines resulting in a loss of confidentiality, integrity, and/or availability.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Upgrade to version krb5-1.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.