PT-2007-1053 · Mit+3 · Krb5-Devel+9

Published

2007-06-26

·

Updated

2024-06-15

·

CVE-2007-2798

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: krb5-server-1.5 versions 1.5 krb5-libs-1.5 versions 1.5 mit-krb5 versions prior to 1.5.2-r3 krb5-devel-1.5 versions 1.5 MIT Kerberos versions 1.5.3, 1.6.1 krb5-1.5 versions 1.5 krb5-workstation-1.5 versions 1.5
Description: The issue concerns multiple vulnerabilities in the krb5 package of Red Hat Enterprise Linux and Gentoo Linux, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A specific vulnerability is a stack-based buffer overflow in the rename principal 2 svc function in kadmind for MIT Kerberos, allowing remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
Recommendations: For krb5-server-1.5 version 1.5, update to a version that includes the fix for the vulnerability. For krb5-libs-1.5 version 1.5, update to a version that includes the fix for the vulnerability. For mit-krb5 versions prior to 1.5.2-r3, update to version 1.5.2-r3 or later. For krb5-devel-1.5 version 1.5, update to a version that includes the fix for the vulnerability. For MIT Kerberos versions 1.5.3 and 1.6.1, update to a version that includes the fix for the vulnerability. For krb5-1.5 version 1.5, update to a version that includes the fix for the vulnerability. For krb5-workstation-1.5 version 1.5, update to a version that includes the fix for the vulnerability. As a temporary workaround, consider restricting access to the rename principal 2 svc function in kadmind until a patch is available.

Exploit

Fix

Access of Uninitialized Pointer

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06279
BDU:2015-06283
BDU:2015-06286
BDU:2015-06290
BDU:2015-06294
BDU:2015-09574
CVE-2007-2798
DSA-1323-1
HPSBUX02544
OPENSUSE-SU-2024:10899-1
RHSA-2007:0384
RHSA-2007:0562
RHSA-2007_0562

Affected Products

Gentoo Linux
Hp-Ux
Mit Kerberos
Red Hat
Krb5
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation
Mit-Krb5