Junglewise Threat Intelligence

CVE-1999-1296: MIT Kerberos buffer overflow in Kerberos IV compatibility library

CVE-1999-1296 · Severity: high · CVSS 7.2 · Published 1997-04-29

Technologies: Openbsd, Mit Kerberos 5. Vendors: OpenBSD, Mit.

Executive brief

A vulnerability in the Kerberos authentication system allows local users to gain full administrative (root) control over a computer. Kerberos is a widely used service for verifying user identities across a network. By manipulating a specific configuration setting, a standard user can trigger a memory error that grants them elevated privileges, potentially leading to unauthorized access to sensitive data or system-wide disruption.

Technical details

A buffer overflow exists in the Kerberos IV compatibility library (specifically within src/lib/krb4/g_krbhst.c) due to insufficient bounds checking when reading configuration files. The vulnerability is triggered when the krb_get_krbhst function uses fscanf to read from a file specified by the KRB_CONF environment variable into a fixed-size buffer (linebuf). A local attacker can exploit this by pointing the environment variable to a malicious configuration file containing an excessively long line. If a setuid or setgid program (such as a Kerberized rlogin) utilizes these library functions, the attacker can overwrite the stack and execute arbitrary code with root privileges. This issue affects MIT Kerberos V 1.0, KTH 0.9.3, OpenBSD 2.0, and Cygnus R3 distributions.

Affected products

  • MIT Kerberos 5 1.0
  • MIT Kerberos 4 compatibility library 1.0
  • KTH KTH Kerberos 4 0.9.3
  • OpenBSD OpenBSD 2.0
  • Cygnus Cygnus Kerberos 4 (Bones) R3

Timeline

  • 1997-04-29: disclosed: Advisory released by Secure Networks Inc.
  • 1997-04-29: advisory: NVD publication date

References

Related threats