|
|
Log in / Subscribe / Register

krb5: multiple vulnerabilities

Package(s):krb5 CVE #(s):CVE-2007-0956 CVE-2007-0957 CVE-2007-1216
Created:April 3, 2007 Updated:March 24, 2008
Description: A flaw was found in the username handling of the MIT krb5 telnet daemon (telnetd). A remote attacker who can access the telnet port of a target machine could log in as root without requiring a password. MIT krb5 Security Advisory 2007-001

Buffer overflows were found which affect the Kerberos KDC and the kadmin server daemon. A remote attacker who can access the KDC could exploit this bug to run arbitrary code with the privileges of the KDC or kadmin server processes. MIT krb5 Security Advisory 2007-002

A double-free flaw was found in the GSSAPI library used by the kadmin server daemon. MIT krb5 Security Advisory 2007-003

Alerts:
Mandriva MDKSA-2007:077-1 krb5 2007-04-10
Foresight FLEA-2007-0008-1 krb5 2007-04-05
SuSE SUSE-SA:2007:025 krb5 2007-04-05
Mandriva MDKSA-2007:077 krb5 2006-04-04
rPath rPSA-2007-0063-1 krb5 2007-04-04
Ubuntu USN-449-1 krb5 2007-04-04
Gentoo 200704-02 mit-krb5 2007-04-03
Fedora FEDORA-2007-409 krb5 2007-04-03
Fedora FEDORA-2007-408 krb5 2007-04-03
Debian DSA-1276-1 krb5 2007-04-03
Red Hat RHSA-2007:0095-01 krb5 2007-04-03

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds