PT-2007-1083 · Mit+1 · Mit-Krb5+1

Publicado

2007-04-03

·

Atualizado

2024-06-15

·

CVE-2007-0957

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: MIT krb5 versions prior to 1.6.1
Description: The issue is related to a stack-based buffer overflow in the krb5 klog syslog function within the kadm5 library. This library is used by the Kerberos administration daemon (kadmind) and the Key Distribution Center (KDC). The overflow can be triggered by remote authenticated users who provide crafted arguments, potentially involving certain format string specifiers. This could allow the execution of arbitrary code and modification of the Kerberos key database.
Recommendations: For versions prior to 1.6.1, update to version 1.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the krb5 klog syslog function until a patch is available.

Correção

Memory Corruption

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09557
CVE-2007-0957
DSA-1276-1
OPENSUSE-SU-2024:10899-1
RHSA-2007:0095
RHSA-2007_0095

Produtos afetados

Mit-Krb5
Red Hat