CVE-2004-1189 is a heap-based buffer overflow vulnerability in the add_to_history function of libkadm5srv in MIT Kerberos 5 versions up to 1.3.5. This flaw occurs during password changes, where improper tracking of password policy history and key counts leads to an array index out-of-bounds error. Authenticated users can exploit this to potentially execute arbitrary code. With a CVSS score of 7.2, this vulnerability is considered high severity, allowing local attackers (AV:L) with low attack complexity (AC:L) to achieve full confidentiality, integrity, and availability impacts (C:C/I:C/A:C). Despite its age, its FAUCET Risk Score of 84/100 indicates a significant potential risk. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. However, the vulnerability has garnered significant community discussion, with 10 mentions, suggesting ongoing awareness or interest, despite a lack of media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.5CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.