Show filters
156 Total Results
Displaying 91-100 of 156
Sort by:
Attacker Value
Unknown

CVE-2007-5972

Disclosure Date: December 06, 2007 (last updated October 04, 2023)
Double free vulnerability in the krb5_def_store_mkey function in lib/kdb/kdb_default.c in MIT Kerberos 5 (krb5) 1.5 has unknown impact and remote authenticated attack vectors. NOTE: the free operations occur in code that stores the krb5kdc master key, and so the attacker must have privileges to store this key.
0
Attacker Value
Unknown

CVE-2007-5902

Disclosure Date: December 06, 2007 (last updated October 04, 2023)
Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request.
0
Attacker Value
Unknown

CVE-2007-5971

Disclosure Date: December 06, 2007 (last updated October 04, 2023)
Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2007-5894

Disclosure Date: December 06, 2007 (last updated November 08, 2023)
The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used. NOTE: the vendor disputes this issue, stating " The 'length' variable is only uninitialized if 'auth_type' is neither the 'KERBEROS_V4' nor 'GSSAPI'; this condition cannot occur in the unmodified source code.
0
Attacker Value
Unknown

CVE-2007-4743

Disclosure Date: September 06, 2007 (last updated October 04, 2023)
The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and other applications that use krb5, does not correctly check the buffer length in some environments and architectures, which might allow remote attackers to conduct a buffer overflow attack.
0
Attacker Value
Unknown

CVE-2007-3999

Disclosure Date: September 05, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.
0
Attacker Value
Unknown

CVE-2007-4000

Disclosure Date: September 05, 2007 (last updated February 09, 2024)
The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.
0
Attacker Value
Unknown

CVE-2007-2443

Disclosure Date: June 26, 2007 (last updated October 04, 2023)
Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.
0
Attacker Value
Unknown

CVE-2007-2798

Disclosure Date: June 26, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
0
Attacker Value
Unknown

CVE-2007-2442

Disclosure Date: June 26, 2007 (last updated October 04, 2023)
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.
0