krb5: multiple vulnerabilities
| Package(s): | krb5 | CVE #(s): | CVE-2007-0956 CVE-2007-0957 CVE-2007-1216 | ||||||||||||||||||||||||||||||||||||||||||||
| Created: | April 3, 2007 | Updated: | March 24, 2008 | ||||||||||||||||||||||||||||||||||||||||||||
| Description: | A flaw was found in the username handling of the MIT krb5 telnet daemon
(telnetd). A remote attacker who can access the telnet port of a target
machine could log in as root without requiring a password. MIT krb5 Security Advisory 2007-001
Buffer overflows were found which affect the Kerberos KDC and the kadmin server daemon. A remote attacker who can access the KDC could exploit this bug to run arbitrary code with the privileges of the KDC or kadmin server processes. MIT krb5 Security Advisory 2007-002 A double-free flaw was found in the GSSAPI library used by the kadmin server daemon. MIT krb5 Security Advisory 2007-003 | ||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||
