9.8

CVE-2008-0062

KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.

Data is provided by the National Vulnerability Database (NVD)
MitKerberos 5 Version <= 1.6.3
DebianDebian Linux Version3.1
DebianDebian Linux Version4.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version6.10
CanonicalUbuntu Linux Version7.04
CanonicalUbuntu Linux Version7.10
FedoraprojectFedora Version7
FedoraprojectFedora Version8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 13.21% 0.939
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-665 Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

http://www.securityfocus.com/archive/1/493080/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/archive/1/489883/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.kb.cert.org/vuls/id/895609
Third Party Advisory
US Government Resource
http://www.securityfocus.com/archive/1/489761
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/28303
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1019626
Third Party Advisory
Broken Link
VDB Entry