PT-2007-1083 · Mit+1 · Mit-Krb5+1

Published

2007-04-03

·

Updated

2024-06-15

·

CVE-2007-0957

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: MIT krb5 versions prior to 1.6.1
Description: The issue is related to a stack-based buffer overflow in the krb5 klog syslog function within the kadm5 library. This library is used by the Kerberos administration daemon (kadmind) and the Key Distribution Center (KDC). The overflow can be triggered by remote authenticated users who provide crafted arguments, potentially involving certain format string specifiers. This could allow the execution of arbitrary code and modification of the Kerberos key database.
Recommendations: For versions prior to 1.6.1, update to version 1.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the krb5 klog syslog function until a patch is available.

Fix

Memory Corruption

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09557
CVE-2007-0957
DSA-1276-1
OPENSUSE-SU-2024:10899-1
RHSA-2007:0095
RHSA-2007_0095

Affected Products

Mit-Krb5
Red Hat