PT-2007-1084 · Mit+2 · Kadmind+5

Publicado

2007-04-03

·

Atualizado

2024-06-15

·

CVE-2007-1216

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: MIT krb5 versions prior to 1.6.1
Description: The issue is related to a double free vulnerability in the GSS-API library, specifically in the k5unseal.c file, which is used by the Kerberos administration daemon (kadmind) when the authentication method provided by the RPCSEC GSS RPC library is utilized. This vulnerability allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an invalid direction encoding.
Recommendations: For MIT krb5 versions prior to 1.6.1, update to version 1.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the kadmind daemon until a patch is applied.

Correção

Double Free

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09557
CVE-2007-1216
DSA-1276-1
HPSBUX02217
OPENSUSE-SU-2024:10899-1
RHSA-2007:0095
RHSA-2007_0095

Produtos afetados

Gssapi
Hp-Ux
Mit-Krb5
Rpcsec Gss
Red Hat
Kadmind