PT-2007-1052 · Mit+2 · Krb5-Devel+8

Wei Wang

·

Published

2007-06-26

·

Updated

2021-02-02

·

CVE-2007-2443

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: MIT Kerberos 5 (krb5) versions 1.6.1 and earlier krb5-server-1.5 krb5-libs-1.5 krb5-devel-1.5 krb5-1.5 krb5-workstation-1.5 mit-krb5 versions prior to 1.5.2-r3
Description: The issue is related to multiple vulnerabilities in the krb5 package, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely. Specifically, an integer signedness error in the gssrpc svcauth unix function in svc auth unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.
Recommendations: For MIT Kerberos 5 (krb5) versions 1.6.1 and earlier, consider updating to a version later than 1.6.1. For krb5-server-1.5, krb5-libs-1.5, krb5-devel-1.5, krb5-1.5, and krb5-workstation-1.5, update to a version later than 1.5. For mit-krb5 versions prior to 1.5.2-r3, update to version 1.5.2-r3 or later. As a temporary workaround, consider restricting access to the gssrpc svcauth unix function in the RPC library until a patch is available.

Exploit

Fix

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06279
BDU:2015-06283
BDU:2015-06286
BDU:2015-06290
BDU:2015-06294
BDU:2015-09574
CVE-2007-2443
DSA-1323-1
HPSBUX02544
RHSA-2007:0384
RHSA-2007:0562
RHSA-2007_0562

Affected Products

Hp-Ux
Mit Kerberos 5
Red Hat
Krb5
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation
Mit-Krb5