PT-2007-1083 · Mit+1 · Mit-Krb5+1
Published
2007-04-03
·
Updated
2024-06-15
·
CVE-2007-0957
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
MIT krb5 versions prior to 1.6.1
Description:
The issue is related to a stack-based buffer overflow in the
krb5 klog syslog function within the kadm5 library. This library is used by the Kerberos administration daemon (kadmind) and the Key Distribution Center (KDC). The overflow can be triggered by remote authenticated users who provide crafted arguments, potentially involving certain format string specifiers. This could allow the execution of arbitrary code and modification of the Kerberos key database.Recommendations:
For versions prior to 1.6.1, update to version 1.6.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
krb5 klog syslog function until a patch is available.Fix
Memory Corruption
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mit-Krb5
Red Hat