CVE-2004-1189

Source
https://cve.org/CVERecord?id=CVE-2004-1189
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2004-1189.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2004-1189
Downstream
Withdrawn
2026-01-27T04:05:39.255519Z
Published
2004-12-31T05:00:00Z
Modified
2026-01-27T04:05:39.255519Z
Summary
[none]
Details

The addtohistory function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.

References

Affected packages