PT-2008-1050 · Mit+1 · Mit Kerberos 5+1

Published

2008-03-18

·

Updated

2024-02-09

·

CVE-2008-0063

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (krb5kdc) versions prior to the fixed version Red Hat Enterprise Linux (affected versions not specified)
Description The issue is related to the Kerberos 4 support in the KDC component of MIT Kerberos 5, where the unused portion of a buffer is not properly cleared when generating an error message. This might allow remote attackers to obtain sensitive information. The problem can lead to a violation of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely.
Recommendations For MIT Kerberos 5, update to a version that includes the fix for the buffer clearing issue. For Red Hat Enterprise Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Initialization

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06278
CVE-2008-0063
DSA-1524-1
RHSA-2008:0164
RHSA-2008:0180
RHSA-2008:0181
RHSA-2008:0182
RHSA-2008_0164
RHSA-2008_0180

Affected Products

Mit Kerberos 5
Red Hat