PT-2007-1108 · Mit+1 · Mit Kerberos 5+1

Published

2007-09-04

·

Updated

2024-06-15

·

CVE-2007-4000

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: mit-krb5 versions prior to 1.5.3 mit-krb5 versions 1.5 through 1.6.2
Description: The issue affects the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5). It is related to the kadm5 modify policy internal function in lib/kadm5/srv/svr policy.c, which does not properly check return values when the policy does not exist. This might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer. Exploitation of the vulnerabilities can lead to a violation of confidentiality, integrity, and availability of protected information and can be performed remotely.
Recommendations: For mit-krb5 versions prior to 1.5.3, update to version 1.5.3 or later. For mit-krb5 versions 1.5 through 1.6.2, update to a version later than 1.6.2. As a temporary workaround, consider restricting access to the kadm5 modify policy internal function in the Kerberos administration daemon until a patch is available.

Fix

Buffer Overflow

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09590
CVE-2007-4000
OPENSUSE-SU-2024:10899-1
RHSA-2007:0858
RHSA-2007_0858

Affected Products

Mit Kerberos 5
Red Hat