9

CVE-2007-2798

Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.

Data is provided by the National Vulnerability Database (NVD)
MitKerberos 5 Version <= 1.6.1
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version6.10
CanonicalUbuntu Linux Version7.04
DebianDebian Linux Version3.1
DebianDebian Linux Version4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 14.89% 0.942
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://www.securityfocus.com/bid/25159
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-177A.html
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/554257
Patch
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/24653
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1018295
Third Party Advisory
VDB Entry