Jump to content

Advisories MDKSA-2007:137: Updated krb5 packages fix vulnerabilities


paul
 Share

Recommended Posts

David Coffey discovered an uninitialized pointer free flaw in the

RPC library used by kadmind. A remote unauthenticated attacker who

could access kadmind could trigger the flaw causing kadmind to crash

or possibly execute arbitrary code (CVE-2007-2442).

 

David Coffey also discovered an overflow flaw in the same RPC library.

A remote unauthenticated attacker who could access kadmind could

trigger the flaw causing kadmind to crash or possibly execute arbitrary

code (CVE-2007-2443).

 

Finally, a stack buffer overflow vulnerability was found in kadmind

that allowed an unauthenticated user able to access kadmind the

ability to trigger the vulnerability and possibly execute arbitrary

code (CVE-2007-2798).

 

Updated packages have been patched to prevent this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...