PT-2008-1050 · Mit+1 · Mit Kerberos 5+1
Publicado
2008-03-18
·
Atualizado
2024-02-09
·
CVE-2008-0063
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MIT Kerberos 5 (krb5kdc) versions prior to the fixed version
Red Hat Enterprise Linux (affected versions not specified)
Description
The issue is related to the Kerberos 4 support in the KDC component of MIT Kerberos 5, where the unused portion of a buffer is not properly cleared when generating an error message. This might allow remote attackers to obtain sensitive information. The problem can lead to a violation of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely.
Recommendations
For MIT Kerberos 5, update to a version that includes the fix for the buffer clearing issue.
For Red Hat Enterprise Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Initialization
Use of Uninitialized Resource
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mit Kerberos 5
Red Hat